T09 · Insecure Skill Coding Practices
- Location
src/config.js:17- Finding
Bearer Tokens and Authentication Responses Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
src/config.js:17-20, with credential transmission insrc/client.js:50-74andcli.js:386-393
Vulnerability Type: Plaintext transmission of authentication credentials
Risk Level: HighVulnerable Code
src/config.js:17-20configures a public plaintext HTTP endpoint as the default:javascript const DEFAULT_BASE_URL = 'http://st.aidata366.com';src/client.js:50-74warns about HTTP but proceeds to transmit the bearer token:javascript if (!_httpWarned && this.token && this.baseUrl.startsWith('http://')) { _httpWarned = true; process.stderr.write('[warn] 当前服务地址为明文 http,token 会明文传输,建议确认网络安全或切换 https\n'); } res = await fetch(this.baseUrl + '/api/v1' + apiPath, { method, headers: { ...(body ? { 'Content-Type': 'application/json' } : {}), ...(this.token ? { Authorization: `Bearer ${this.token}` } : {}), ...headers, }, body: body ? JSON.stringify(body) : undefined, signal: ctrl.signal, });cli.js:386-393also sends the bearer token over the configured endpoint when downloading an export:javascript const dlCtrl = new AbortController(); const dlTimer = setTimeout(() => dlCtrl.abort(), DOWNLOAD_TIMEOUT_MS); let buf; try { const res = await fetch(`${cfg.baseUrl}/api/v1/platform/exports/${encodeURIComponent(info.export_id)}/file`, { headers: { Authorization: `Bearer ${cfg.token}` }, signal: dlCtrl.signal });Technical Analysis
The default base URL uses unencrypted HTTP for a remote public service. Authenticated API methods attach a reusable bearer token to the
Authorizationheader, while session-check responses can return the token through the same unencrypted channel.HTTP provides neither transport confidentiality nor server authentication. An attacker able to observe or modify traffic between the host running the Skill and the configured service can read bearer credentials, alter API responses, or substitute exported content.
The warning w ...[truncated 2061 chars]
- Remediation
View remediation
Remediation Suggestions
- Deploy a correctly configured HTTPS endpoint and change
DEFAULT_BASE_URLto anhttps://URL. - Reject authenticated requests to non-HTTPS remote destinations. If HTTP support is required for development, restrict it to loopback addresses such as
127.0.0.1,::1, andlocalhost. - Apply the same HTTPS enforcement to login, registration-session checks, authenticated API calls, and export downloads.
- Do not rely on a standard-error warning as the security control. Fail closed before transmitting access tokens or receiving authentication credentials over HTTP.
- Remove the process-wide
NODE_TLS_REJECT_UNAUTHORIZED=0mechanism where possible. If private certificate authorities are required, configure an explicit trusted CA instead of disabling certificate validation globally. - After deploying HTTPS enforcement, revoke or rotate tokens that may previously have traversed untrusted plaintext networks.
- Add automated tests verifying that bearer-authenticated requests and authentication-session checks reject remote
http://base URLs.
- Deploy a correctly configured HTTPS endpoint and change
