T09 · Insecure Skill Coding Practices
- Location
scripts/ima_voice_create.py:862- Finding
Arbitrary API Base URL Can Exfiltrate the Bearer Credential and User Prompt
- Content
View full analysis
dict: return { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json", "User-Agent": "IMA-OpenAPI-Client/Skill-1.0.2", "x-app-source": "ima_skills", "x_app_language": language, } ``` ```python url = f"{base_url}/open/v1/product/list" params = {"app": app, "platform": platform, "category": TASK_TYPE} headers = make_headers(api_key, language) logger.info(f"Query product list: category={TASK_TYPE}, app={app}, platform={platform}") try: resp = requests.get(url, params=params, headers=headers, timeout=30) ``` ```python url = f"{base_url}/open/v1/tasks/create" headers = make_headers(api_key) logger.info(f"Create task: model={model_params['model_name']}, task_type={TASK_TYPE}, " f"credit={model_params['credit']}, attribute_id={model_params['attribute_id']}") try: resp = requests.post(url, json=payload, headers=headers, timeout=30) ``` ```python url = f"{base_url}/open/v1/tasks/create" headers = make_headers(api_key) logger.info(f"Attempt {attempt_num}: attribute_id={attribute_id}, credit={credit}, params={list(candidate_params.keys())}") try: resp = requests.post(url, json=payload, headers=headers, timeout=30) ``` ```python p.add_argument("--base-url", default=DEFAULT_BASE_URL, help="API base URL") ``` ### Technical Analysis The Skill needs network access to `https://api.imastudio.c ...[truncated 2455 chars]- Remediation
View remediation
