T09 · Insecure Skill Coding Practices
- Location
src/config.js:19- Finding
Bearer tokens and task data are transmitted over plaintext HTTP by default
- Content
View full analysis
Vulnerability Details
File Location:
src/config.js:19-22, with authenticated request sinks atsrc/client.js:66-72andcli.js:292-293
Vulnerability Type: Plaintext transmission of credentials and sensitive data
Risk Level: HighTechnical Analysis
The built-in service endpoint uses unencrypted HTTP:
js // Server certificate is not ready, so HTTP remains the default. const DEFAULT_BASE_URL = 'http://st.aidata366.com';resolveConfig()uses this endpoint unless it is overridden through command-line options, an environment variable, or the configuration file. Authenticated API requests then attach the reusable bearer token to requests sent to that endpoint:js res = await fetch(this.baseUrl + '/api/v1' + apiPath, { method, headers: { ...(body ? { 'Content-Type': 'application/json' } : {}), ...(this.token ? { Authorization: `Bearer ${this.token}` } : {}), ...headers, }, body: body ? JSON.stringify(body) : undefined, signal: ctrl.signal, });The export download path independently sends the same credential:
js const res = await fetch( `${cfg.baseUrl}/api/v1/platform/exports/${encodeURIComponent(info.export_id)}/file`, { headers: { Authorization: `Bearer ${cfg.token}` }, signal: dlCtrl.signal } );Although
src/client.jsemits a warning when a token is sent over HTTP, the warning does not require confirmation or stop the request. Consequently, authenticated commands using the default configuration expose credentials and application data to passive interception and active modification.This affects commands including
submit,query,quota,export, andlogout. Registration and login session exchanges also use the configured endpoint.Attack Path
- A user invokes the Skill without overriding its default base URL.
- The CLI resolves the endpoint to
http://st.aidata366.com. - The user logs ...[truncated 1082 chars]
- Remediation
View remediation
Remediation Suggestions
- Configure a valid TLS certificate and change
DEFAULT_BASE_URLto anhttps://endpoint. - Reject plaintext HTTP whenever a bearer token, login-session value, submitted URL, task result, profile response, or export is involved.
- Validate the URL with the
URLparser and require thehttps:scheme rather than relying on a prefix check. - If HTTP support is unavoidable for isolated development environments, require an explicit per-invocation opt-in and prohibit sending production credentials through that mode.
- Do not treat a stderr warning as an adequate security boundary; fail closed before constructing authenticated requests.
- Ensure export downloads apply the same centralized HTTPS enforcement as other API requests.
- After migrating to HTTPS, revoke or rotate tokens that may previously have traversed untrusted networks over HTTP.
- Configure a valid TLS certificate and change
