T09 · Insecure Skill Coding Practices
- Location
scripts/cordys.py:529- Finding
CRM Credentials Can Be Transmitted to an Arbitrary External Domain
- Content
View full analysis
str: """Execute API request.""" check_keys() headers = { "X-Access-Key": CORDYS_ACCESS_KEY, "X-Secret-Key": CORDYS_SECRET_KEY, "X-Request-Source": "SKILL", "Content-Type": f"{content_type}; charset=utf-8" } ``` ```python def raw_api(method: str, path: str, *args) -> str: """Execute raw API request.""" if path.startswith("http"): if not validate_url(path): print("Request rejected: target domain does not match configured Cordys CRM domain", file=sys.stderr) print(f"Configured domain: {CORDYS_CRM_DOMAIN}", file=sys.stderr) print("To force sending, set CORDYS_ALLOW_UNTRUSTED=1", file=sys.stderr) if os.environ.get("CORDYS_ALLOW_UNTRUSTED", "0") != "1": sys.exit(1) else: warn("Untrusted-domain mode enabled; continuing request") url = path else: url = f"{CORDYS_CRM_DOMAIN}{path}" return api(method, url) ``` The equivalent shell behavior is: ```bash raw_api() { local method="$1" path="$2" shift 2 if [[ "$path" == http* ]]; then if ! validate_url "$path"; then echo "Request rejected: target domain does not match configured Cordys CRM domain" >&2 echo "Configured domain: $CORDYS_CRM_DOMAIN" >&2 if [[ "${CORDYS_ALLOW_UNTRUSTED:-0}" != "1" ]]; then exit 1 else warn "Untrusted-domain mode enabled; continuing request" fi fi api "$method" "$path" "$@" else api "$method" "${CORDYS_CRM_DOMAIN}${path}" "$@" fi } ``` ...[truncated 1974 chars]- Remediation
View remediation
