T09 · Insecure Skill Coding Practices
- Location
mtf_momentum.py:254- Finding
Trading API Credential Can Be Transmitted to an Arbitrary Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
mtf_momentum.py:67,mtf_momentum.py:254-262
Vulnerability Type: Credential disclosure through an unrestricted, configurable network destination
Risk Level: HighVulnerable Code
python SIMMER_API_URL = os.environ.get("SIMMER_API_URL", "https://api.simmer.markets")python def fetch_fast_markets(): """Fetch active fast markets for the configured asset from Simmer API.""" try: api_key = os.environ.get("SIMMER_API_KEY", "") req = Request( f"{SIMMER_API_URL}/api/sdk/fast-markets?asset={ASSET}&window=5m&limit=10", headers={"Authorization": f"Bearer {api_key}"}, ) data = json.loads(urlopen(req, timeout=10).read()) return data.get("markets", []) except Exception as e: print(f" Failed to fetch fast markets: {e}") return []Technical Analysis
The program obtains
SIMMER_API_URLfrom an unrestricted environment variable and sendsSIMMER_API_KEYto that destination as a bearer credential. It does not validate the URL scheme, hostname, port, or effective destination after redirects.Configurability of a credential-bearing endpoint is not required for the declared momentum calculation or trading functionality. Anyone able to influence the process environment can redirect the request to an attacker-controlled HTTP or HTTPS server. Allowing plaintext HTTP also permits disclosure to a network observer.
This behavior explains the sensitive-network-flow pre-scan result. Sending the key to the legitimate Simmer service is necessary, but allowing an arbitrary destination exceeds the minimum trust boundary required by the Skill.
Attack Path
- An attacker, compromised launcher, deployment configuration, or automation environment sets
SIMMER_API_URLto an attacker-controlled address, such ashttps://attacker.example. - The user supp ...[truncated 1285 chars]
- An attacker, compromised launcher, deployment configuration, or automation environment sets
- Remediation
View remediation
Remediation Suggestions
- Remove the unrestricted
SIMMER_API_URLoverride and use a fixed trusted endpoint:python SIMMER_API_URL = "https://api.simmer.markets" - If endpoint configurability is operationally necessary, parse the URL and enforce:
- Scheme exactly equal to
https. - Hostname present in a small explicit allowlist.
- No embedded user information.
- An approved port, normally 443.
- Scheme exactly equal to
- Reject redirects for authenticated requests, or implement redirect handling that strips authorization headers and only permits same-origin HTTPS redirects.
- Construct authenticated requests through a centralized client that applies destination validation before adding credentials.
- Use a narrowly scoped API key with only the permissions required for market discovery and intended trades.
- Support immediate key revocation and rotation, and rotate any key that may have been used with an untrusted endpoint.
- Do not log the authorization header or API key in errors, debug traces, or automation reports.
- Add tests proving that HTTP URLs, unapproved hosts, nonstandard ports, and cross-origin redirects are rejected before the credential is attached.
- Remove the unrestricted
