T09 · Insecure Skill Coding Practices
- Location
scripts/query_orders.py:227- Finding
Phone Numbers Are Exposed in GET URLs and Debug Logs
- Content
View full analysis
Vulnerability Details
File Locations:
scripts/query_orders.py:227-238scripts/recommend_drink.py:177-184scripts/claim_reward.py:149-160
Vulnerability Type: Sensitive information exposure through URL query parameters and debug logging
Risk Level: MediumVulnerable Code
scripts/query_orders.py:227-238:python query = { "mobile": resolved_mobile, "status": args.status, } orders_url = build_url( config["apiBaseUrl"].rstrip("/"), "/skill/xinyi/orders", query, ) debug_log(args.debug, f"fetching orders from {orders_url}") try: orders_response = fetch_json(orders_url, config["timeoutSeconds"])scripts/recommend_drink.py:177-184:python context_url = build_url( base_url, "/skill/xinyi/context", {"mobile": resolved_mobile}, ) debug_log(args.debug, f"fetching context from {context_url}") try: context_response = fetch_json(context_url, timeout)scripts/claim_reward.py:149-160:python context_url = build_url( base_url, "/skill/xinyi/context", {"mobile": resolved_mobile}, ) try: debug_log(args.debug, f"fetching context from {context_url}") context_response = fetch_json( context_url, config["timeoutSeconds"], )Technical Analysis
The order and personalized-context endpoints place the user's phone number in the URL query string. The resulting complete URL is also written to standard error when debug mode is enabled.
HTTPS protects the URL while it is in transit, but it does not prevent the URL from being recorded at either endpoint. Query strings are frequently retained in:
- Reverse-proxy and web-server access logs
- API gateway and load-balancer logs
- Monitoring, tracing, and error-reporting systems
- Debug output captured by an Agent runtime
- Shell transcripts and continuous-integration logs
- Network-security ...[truncated 1632 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace phone-number-bearing GET requests with POST requests whose identifiers are carried in a JSON body.
-
Require HTTPS for every endpoint that receives personal data. Validate the configured URL scheme and reject plaintext HTTP except for explicitly enabled local testing.
-
Never log complete URLs containing personal identifiers. Log only the endpoint path or a sanitized URL:
python debug_log(args.debug, "fetching orders from /skill/xinyi/orders") -
If correlation is necessary, use a short-lived request identifier rather than the phone number. Do not log a reversible encoding of the number.
-
Configure backend servers, proxies, gateways, monitoring platforms, and tracing systems to suppress request bodies and sensitive query parameters.
-
Add automated tests asserting that debug output never contains the supplied or saved phone number.
-
Review existing logs for retained phone numbers and remove or restrict them according to the applicable privacy and retention requirements.
-
