T09 · Insecure Skill Coding Practices
- Location
scripts/zhitou.mjs:10- Finding
Configurable API Origin Can Expose the Bearer Credential and Submitted Data
- Content
View full analysis
Vulnerability Details
File Location:
scripts/zhitou.mjs:10-22
Vulnerability Type: Arbitrary credential-bearing API destination
Risk Level: MediumVulnerable Code
js const BASE = (process.env.WOHAONIU_BASE_URL || 'https://ai.wohaoniu.com').replace(/\/$/, ''); const KEY = process.env.WOHAONIU_API_KEY || ''; const die = (msg) => { console.error(msg); process.exit(1); }; if (!KEY) die('未配置 WOHAONIU_API_KEY —— 到 https://ai.wohaoniu.com → 个人中心 → 开放接口 生成密钥后配置到环境变量。'); async function call(path, body) { const res = await fetch(BASE + path, { method: body ? 'POST' : 'GET', headers: { 'content-type': 'application/json', authorization: `Bearer ${KEY}` }, body: body ? JSON.stringify(body) : undefined, signal: AbortSignal.timeout(110_000), });Technical Analysis
The complete API origin is taken from the undocumented
WOHAONIU_BASE_URLenvironment variable. The program does not validate the URL scheme or restrict the destination hostname before attachingWOHAONIU_API_KEYas a bearer credential.Consequently, a party capable of influencing the Skill process environment can redirect the initial request to an arbitrary HTTP or HTTPS server. That server receives the API key in the
Authorizationheader. For commands that accept user input, it also receives the submitted brand, category, product description, target audience, or advertising brief.The override may be useful for legitimate testing, but allowing unrestricted destinations is not necessary for the declared production functionality. It violates least-privilege principles because a credential issued for
ai.wohaoniu.comcan be disclosed to an unrelated origin.Attack Path
- An attacker gains the ability to modify the environment used to launch the Skill, such as through a compromised launcher, deployment configuration, shell profile, or environment file.
- The attacker sets `WOHAONIU_BASE_ ...[truncated 1104 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
WOHAONIU_BASE_URLfrom production builds and use a fixed API origin:js const BASE = 'https://ai.wohaoniu.com'; - If an override is required for development, enable it only under an explicit development mode and never reuse production credentials.
- Parse the URL and enforce both an HTTPS scheme and an exact hostname allowlist before sending credentials.
- Reject URLs containing unexpected credentials, ports, protocols, or hostnames.
- Configure redirect handling defensively and ensure authorization headers are never forwarded to a different origin.
- Use separate, minimally scoped test credentials for non-production endpoints.
- Document every supported configuration variable and its security consequences.
- Revoke and replace any API key that may have been used while an untrusted base URL was configured.
- Remove
