T09 · Insecure Skill Coding Practices
- Location
scripts/skill.py:9- Finding
API Key Can Be Transmitted over Plaintext HTTP
- Content
View full analysis
httpx.Client: headers = {} if API_KEY: headers["X-API-Key"] = API_KEY return httpx.Client(base_url=BASE_URL, headers=headers, timeout=30.0) ``` ### Technical Analysis The exchange base URL is read from the user-controlled `AGENT_METAVERSE_BASE_URL` environment variable without validating its scheme or destination. The HTTP client then automatically adds the `X-API-Key` header to authenticated requests. Although the default `http://localhost:8000` endpoint is reasonable for local development, the client also accepts a remote URL using plaintext HTTP. When that configuration is used, the API key and all request and response data are transmitted without TLS protection. A network adversary capable of observing traffic between the client and server could recover the key. A maliciously configured endpoint would also receive the credential directly. The documentation explicitly permits changing the base URL but does not warn users that authenticated commands should only use HTTPS for remote hosts. ### Attack Path 1. A user, deployment script, or compromised environment sets `AGENT_METAVERSE_BASE_URL` to a remote plaintext URL such as `http://exchange.example`. 2. The user sets `AGENT_METAVERSE_API_KEY` and invokes an authenticated command such as `balance`, `buy`, or `open-long`. 3. `_client()` attaches the API key to the `X-API-Key` request header. 4. The request travels over unencrypted HTTP. 5. A network observer, transparent proxy, or malicious endpoint captures the API key. 6. The attacker reuses the captured key against the exchange API to access the as ...[truncated 684 chars]- Remediation
View remediation
