T09 · Insecure Skill Coding Practices
- Location
scripts/preflight_runtime.py:303- Finding
API Credentials and Document Content Can Be Transmitted over Plaintext HTTP
- Content
View full analysis
dict[str, Any]: config_check = check_endpoint_config(args) if config_check["status"] == "fail": return config_check base_url = str(args.base_url or "").rstrip("/") parsed = urlparse(base_url) if "api.deepseek.com" in parsed.netloc or base_url.endswith("/chat/completions"): return _chat_endpoint_probe(args, base_url) request = Request( base_url + "/models", headers={"Authorization": f"Bearer {args.api_key}", "Accept": "application/json"}, method="GET", ) try: with urlopen(request, timeout=float(args.endpoint_timeout)) as response: ``` The direct translator sends both the credential and document text using the accepted URL: ```python payload: dict[str, Any] = { "model": args.model, "messages": [ {"role": "system", "content": system_prompt}, {"role": "user", "co ...[truncated 2521 chars]- Remediation
View remediation
