T09 · Insecure Skill Coding Practices
- Location
src/index.ts:9- Finding
Configurable Remote Backend Permits Plaintext Transmission of Sensitive Control Data
- Content
View full analysis
{ const url = `${SASHA_DOCTOR_URL}${PREFIX}${endpoint}`; const options: RequestInit = { method, headers: { 'Content-Type': 'application/json' }, }; if (body) { options.body = JSON.stringify(body); } try { const response = await fetch(url, options); return await response.json() as ApiResponse; } catch (error) { return { ok: false, error: (error as Error).message }; } } ``` The streaming endpoint uses the same configurable URL without transport or authentication enforcement: ```typescript const url = `${SASHA_DOCTOR_URL}${PREFIX}/session/send-stream`; try { const response = await fetch(url, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ name, message, timeout: parseInt(options.timeout) }) }); ``` The documentation explicitly suggests an insecure remote endpoint: ```bash # Default: http://127.0.0.1:18795 export SASHA_DOCTOR_URL="http://your-server:port" # Alias also supported: export CLAUDE_CODE_API_URL="http://your-server:port" ``` ### Technical Analysis The backend URL is entirely controlled through `SASHA_DOCTOR_URL`, and the implementation does not: - Require HTTPS for non-loopback destinations. - Restrict the destination to trusted hosts. - Authenticate requests to the backend. - Warn the user when crossing the local trust boundary. - Validate response bodies against endpoint-specific ...[truncated 2047 chars]- Remediation
View remediation
