T09 · Insecure Skill Coding Practices
- Location
scripts/common.sh:10- Finding
API Signature Exposed in URL Query Strings
- Content
View full analysis
Vulnerability Details
File Location:
scripts/common.sh:10-19scripts/company.sh:11-20scripts/macro.sh:10-19scripts/plates.sh:11-20scripts/quote.sh:10-19scripts/search.sh:11-20
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: MediumVulnerable Code
The following pattern appears in every service script:
bash call_mcp() { local tool="$1" local params="$2" curl -s -X POST "${BASE_URL}?signature=${SIGNATURE}" \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ --max-time 30 \ -d "$(jq -n --arg name "$tool" --argjson arguments "$params" \ '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":$name,"arguments":$arguments}}')" }Technical Analysis
FINSTEP_SIGNATUREis explicitly designated as a secret inskill.json, but all scripts append it to the request URL as thesignaturequery parameter.HTTPS protects the complete URL while it is transmitted over the network, but it does not prevent the URL from being recorded at endpoints or intermediary infrastructure. Query strings are commonly retained in web-server access logs, reverse-proxy logs, application telemetry, tracing systems, monitoring platforms, and error reports.
Consequently, infrastructure components that legitimately record request URLs may unintentionally store a reusable authentication credential. The implementation conflicts with the project's own requirement that the signature be handled as confidential data.
Attack Path
- A user configures a valid
FINSTEP_SIGNATUREin the environment. - The user invokes any of the six service scripts.
- The script constructs a URL containing
?signature=<secret>. - FinStep infrastructure, a reverse proxy, or an observability system records the complete request URL.
- An operator or ...[truncated 692 chars]
- Remediation
View remediation
Remediation Suggestions
-
Stop transmitting
FINSTEP_SIGNATUREin the URL. -
Use a secret-bearing HTTP header supported by the server, for example:
bash curl -sS -X POST "$BASE_URL" \ -H "Authorization: Bearer ${SIGNATURE}" \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ --max-time 30 \ --data "$request_body" -
If the API uses a proprietary authentication scheme, place the signature in a dedicated header rather than a query parameter.
-
Configure servers, proxies, monitoring tools, and tracing systems to redact authentication values.
-
Reject query-string credentials server-side after clients have migrated.
-
Review historical logs for exposed signatures, restrict access to those logs, and rotate any credential that may have been recorded.
-
Apply the correction consistently to all six scripts.
-
