T09 · Insecure Skill Coding Practices
- Location
scripts/api_connector.py:166- Finding
Authenticated request configurations permit insecure plaintext HTTP endpoints
- Content
View full analysis
Vulnerability Details
File Location:
scripts/api_connector.py, lines 94-104, 166-184, and 256-267
Vulnerability Type: Missing secure transport validation for authentication credentials
Risk Level: MediumVulnerable Code
python def __init__(self, name: str, api_type: APIType = APIType.REST, endpoint: str = "", method: str = "GET"): """Initialize API connector.""" self.name = name self.api_type = api_type self.endpoint = endpoint self.method = method self.auth_config = AuthConfig() self.pagination_config = PaginationConfig() self.request_headers: Dict[str, str] = {}python def get_request_config(self) -> APIRequest: """Build complete request configuration.""" headers = dict(self.request_headers) # Add authentication headers if self.auth_config.auth_type == AuthType.API_KEY: headers[self.auth_config.api_key_header] = self.auth_config.api_key or "" elif self.auth_config.auth_type == AuthType.BEARER: headers["Authorization"] = f"Bearer {self.auth_config.token}" elif self.auth_config.auth_type == AuthType.BASIC: import base64 credentials = f"{self.auth_config.username}:{self.auth_config.password}" encoded = base64.b64encode(credentials.encode()).decode() headers["Authorization"] = f"Basic {encoded}" return APIRequest( endpoint=self.endpoint, method=self.method, headers=headers, params=dict(self.request_params), body=self.request_body )python def validate_config(self) -> bool: """Validate connector configuration.""" if not self.endpoint: self.errors.append("Endpoint is required") return False if self.api_type == APIType.REST and not self.method: self.errors.append("HTTP method is required for REST API") return False ret ...[truncated 2720 chars]- Remediation
View remediation
Remediation Suggestions
- Parse endpoints with
urllib.parse.urlparseduring validation. - Require the
httpsscheme whenever API-key, bearer, Basic, or OAuth authentication is configured. - Reject malformed URLs, unsupported schemes, missing hostnames, and credentials embedded directly in URLs.
- If plaintext HTTP is necessary for trusted local development, require an explicit option such as
allow_insecure_http=Falseby default and restrict any exception to loopback or an administrator-approved host allowlist. - Validate OAuth token endpoints independently and require HTTPS for them as well.
- Document that
Authorizationand API-key headers must never be included in logs, exceptions, configuration summaries, or serialized diagnostic output. - Add tests confirming that authenticated
http://endpoints are rejected while authenticatedhttps://endpoints are accepted. - Encourage least-privilege, short-lived credentials and provide clear credential-revocation guidance.
Example hardening logic:
python from urllib.parse import urlparse def validate_config(self) -> bool: self.errors.clear() if not self.endpoint: self.errors.append("Endpoint is required") return False parsed = urlparse(self.endpoint) if parsed.scheme not in {"http", "https"} or not parsed.hostname: self.errors.append("Endpoint must be a valid HTTP(S) URL") if ( self.auth_config.auth_type != AuthType.NONE and parsed.scheme != "https" ): self.errors.append( "HTTPS is required when authentication is configured" ) if parsed.username or parsed.password: self.errors.append("Credentials must not be embedded in endpoint URLs") if self.api_type == APIType.REST and not self.method: self.errors.append("HTTP method is required for REST API") return len(self.errors) == 0- Parse endpoints with
