T09 · Insecure Skill Coding Practices
- Location
scripts/client.py:26- Finding
Cleartext HTTP Used for External Market Data API
- Content
View full analysis
Vulnerability Details
File Location:
scripts/client.py:26-48
Additional Locations:SKILL.md:4,SKILL.md:30,SKILL.md:52,SKILL.md:111,SKILL.md:125
Vulnerability Type: Cleartext transmission and unauthenticated transport
Risk Level: Mediumpython def __init__(self, base_url: str = "http://fffy520.gicp.net:8003"): self.base_url = base_url.rstrip("/") def _request(self, path: str, params: dict = None) -> dict: url = f"{self.base_url}{path}" if params: url += "?" + urllib.parse.urlencode( {k: v for k, v in params.items() if v is not None} ) try: with urllib.request.urlopen(urllib.request.Request(url), timeout=30) as resp: return json.loads(resp.read().decode("utf-8")) except urllib.error.HTTPError as e: body = e.read().decode("utf-8", errors="ignore") try: return json.loads(body) except json.JSONDecodeError: return {"code": e.code, "error": body} except Exception as e: return {"code": 500, "error": str(e)}The documentation also consistently directs users to the same cleartext endpoint, for example:
text curl "http://fffy520.gicp.net:8003/api/moneyflow?code=600519&trade_date=20260513"Technical Analysis
The default client endpoint and every documented API example use HTTP rather than HTTPS. HTTP provides no server authentication, transport encryption, or integrity protection. A party capable of observing or modifying network traffic can therefore inspect query parameters and replace API responses before the client parses them.
The client directly decodes and returns received JSON without any application-level signature verification. Consequently, syntactically valid JSON injected by an intermediary is treated as a legitimate response. Configurability of
base_urldoes not mitigate the vulnerable default, and the cl ...[truncated 1353 chars]- Remediation
View remediation
Remediation Suggestions
-
Replace the default endpoint with an HTTPS URL served using a valid certificate:
python def __init__(self, base_url: str = "https://api.example.com"): parsed = urllib.parse.urlparse(base_url) if parsed.scheme != "https": raise ValueError("The API endpoint must use HTTPS") self.base_url = base_url.rstrip("/") -
Configure the API service on a stable, controlled domain with a certificate issued by a trusted certificate authority.
-
Update every URL and
curlexample inSKILL.mdto use the authenticated HTTPS endpoint. -
Do not silently fall back to HTTP when TLS negotiation or certificate validation fails.
-
Never transmit API keys, session tokens, or other credentials through the current HTTP endpoint.
-
For high-integrity financial workflows, consider signed API responses or certificate pinning where operationally appropriate, while maintaining a secure certificate-rotation process.
-
