T09 · Insecure Skill Coding Practices
- Location
async-task.js:120- Finding
Custom push endpoint permits plaintext transmission of bearer tokens and session data
- Content
View full analysis
{ const url = new URL(CUSTOM_PUSH_URL); const lib = url.protocol === 'https:' ? https : http; const data = JSON.stringify({ sessionId: sessionId, content: content, role: 'assistant' }); const headers = { 'Content-Type': 'application/json', 'Content-Length': Buffer.byteLength(data) }; if (CUSTOM_AUTH_TOKEN) { headers['Authorization'] = `Bearer ${CUSTOM_AUTH_TOKEN}`; } const req = lib.request({ hostname: url.hostname, port: url.port || (url.protocol === 'https:' ? 443 : 80), path: url.pathname, method: 'POST', headers: headers }, (res) => { let body = ''; res.on('data', chunk => body += chunk); res.on('end', () => { if (res.statusCode >= 200 && res.statusCode < 300) { resolve(body); } else { reject(new Error(`HTTP ${res.statusCode}: ${body}`)); } }); }); ``` ### Technical Analysis The custom push implementation explicitly selects Node.js's unencrypted `http` module whenever `ASYNC_TASK_PUSH_URL` does not use HTTPS. The request can contain all of the following sensitive values: - The `ASYNC_TASK_AUTH_TOKEN` bearer token - The target session identifier - Agent-generated result or error content - The asserted message role No protocol restriction, TLS requirement, or warning prevents use of an `http:` endpoint. Consequently, an HTTP configuration causes authentication and session information to be transmitted in plaintext. A network-positioned attacker can observe or modify these requests. This issue a ...[truncated 1310 chars]- Remediation
View remediation
