T09 · Insecure Skill Coding Practices
- Location
scripts/_common.sh:11- Finding
Service Key Disclosure Through Unrestricted API Base URL Overrides
- Content
View full analysis
Vulnerability Details
File Location:
scripts/_common.sh, lines 11-12 and 61-82
Vulnerability Type: Credential disclosure through attacker-controlled API endpoints
Risk Level: HighVulnerable Code
bash ARPLTN_BASE="${ARPLTN_BASE:-https://apis.data.go.kr/B552584/ArpltnInforInqireSvc}" MSRSTN_BASE="${MSRSTN_BASE:-https://apis.data.go.kr/B552584/MsrstnInfoInqireSvc}"bash airkorea_get() { local base="$1" path="$2"; shift 2 require_key local enc_key enc_key=$(printf '%s' "$AIRKOREA_SERVICE_KEY" | jq -Rrn '@uri inputs') # ver=1.5 surfaces extra metric flags (so2Flag, coFlag, …) on the realtime endpoints; harmless on others. local qs="serviceKey=${enc_key}&returnType=json&_returnType=json&ver=1.5" local kv k v enc_v for kv in "$@"; do [[ -z "$kv" ]] && continue k="${kv%%=*}" v="${kv#*=}" [[ -z "$v" ]] && continue enc_v=$(printf '%s' "$v" | jq -Rrn '@uri inputs') qs="${qs}&${k}=${enc_v}" done local out http out=$(mktemp) http=$(curl -sS -G -o "$out" -w '%{http_code}' "${base}/${path}?${qs}" || true)Technical Analysis
The two API base URLs are read directly from environment variables without validating their scheme, hostname, port, or path. The shared request function then places
AIRKOREA_SERVICE_KEYin the query string of every request sent to the selected base URL.Consequently, a process capable of influencing
ARPLTN_BASEorMSRSTN_BASEcan redirect authenticated requests to an arbitrary server. Both HTTPS attacker endpoints and plaintext HTTP endpoints are accepted. URL encoding the key does not protect its confidentiality because the receiving server obtains and decodes the query parameter.The overrides are also documented in
SKILL.mdas supported configuration, but the credential-routing implications and trust requirements are not disclosed.Attack Path
...[truncated 1148 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove runtime endpoint overrides unless they are strictly necessary.
- Before attaching credentials, parse and validate the destination URL against an explicit allowlist:
- Require the
httpsscheme. - Require the exact hostname
apis.data.go.kr. - Reject embedded credentials, custom ports, fragments, and unexpected paths.
- Restrict paths to the two expected
/B552584/service prefixes.
- Require the
- If development overrides are required, place them behind an explicit option such as
--allow-unsafe-custom-endpointand do not attach production credentials by default. - Consider separating test credentials from production credentials and requiring a distinct environment variable for custom endpoints.
- Add tests proving that HTTP URLs, lookalike domains, user-info URLs, and unapproved paths are rejected.
- Update
SKILL.mdto explain the trust boundary and discourage endpoint overrides in credential-bearing production use.
