T09 · Insecure Skill Coding Practices
- Location
hifleet-opentonnages/scripts/opentonnages_tool.py:46- Finding
API credentials and query data can be redirected to arbitrary network endpoints
- Content
View full analysis
dict[str, Any]: api_key = os.environ.get("HIFLEET_API_KEY", "").strip() api_base = os.environ.get("HIFLEET_CHARTER_API_BASE", "").strip().rstrip("/") liner_base = os.environ.get("HIFLEET_LINER_API_BASE", "").strip().rstrip("/") enrich_url = os.environ.get("HIFLEET_CHARTER_ENRICH_URL", "").strip() cfg_path = default_skill_dir() / "config.json" if cfg_path.is_file(): try: cfg = json.loads(cfg_path.read_text(encoding="utf-8")) if isinstance(cfg, dict): api_key = api_key or str(cfg.get("hifleet_api_key") or "").strip() if not api_base: api_base = str(cfg.get("hifleet_charter_api_base") or "").strip().rstrip("/") if not liner_base: liner_base = str(cfg.get("hifleet_liner_api_base") or "").strip().rstrip("/") if not enrich_url: enrich_url = str(cfg.get("charter_enrich_url") or "").strip() except (json.JSONDecodeError, OSError): pass if not api_base: root = (os.environ.get("HIFLEET_API_BASE") or "https://api.hifleet.com").rstrip("/") api_base = root + "/openclaw/vessel/charter" if not liner_base: liner_base = DEFAULT_LINER_BASE if not enrich_url: enrich_url = DEFAULT_ENRICH_URL return { "api_key": api_key, "api_base": api_base.rstrip("/"), "liner_base": liner_base.rstrip("/"), "enrich_url": enrich_url, } ``` The resulting endpoints are used without scheme or hostname validation: ```python base = cfg["api_base"] url = f"{base}/{endpoint.lstrip('/')}?{urllib.parse.urlencode({'api_key': api_key})}" ``` ...[truncated 3439 chars]- Remediation
View remediation
