T09 · Insecure Skill Coding Practices
- Location
SKILL.md:48- Finding
Plaintext HTTP Endpoint Permits Financial Data Tampering
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 48–49
Vulnerability Type: Insecure plaintext transport configuration
Risk Level: MediumVulnerable Code
markdown > Base URL:`http://vi-money.com/`(需确认是否为实际对外地址;如未确认,调用方必须先核验协议/端口) > 建议通过环境变量 `STOCK_API_BASE_URL` 覆盖该地址,避免硬编码。Technical Analysis
The Skill specifies an unauthenticated external REST API over plaintext HTTP as its default data source. HTTP does not provide confidentiality, server authentication, or response integrity. Consequently, a network-positioned attacker could intercept requests and modify API responses before they reach the Agent.
Allowing
STOCK_API_BASE_URLto override the endpoint does not secure the default behavior. The documented instructions do not require HTTPS, validate the configured URL scheme, restrict trusted hosts, or authenticate response content.Although the queried stock information is generally public and requests do not contain documented credentials, integrity remains security-sensitive because the Agent is instructed to use the returned records to produce financial summaries.
Attack Path
- A user asks the Agent to analyze A-share or Hong Kong dividend information.
- The Skill directs the Agent to request data from
http://vi-money.com/. - An attacker with a network interception position, such as a compromised gateway or hostile wireless access point, intercepts the plaintext request.
- The attacker returns modified dividend records, yields, dates, company names, or API status fields.
- The Agent treats the manipulated response as authoritative and incorporates it into its financial analysis.
- The user receives inaccurate or attacker-controlled financial information.
Impact Assessment
Exploitation does not directly grant local code execution, filesystem access, elevated system privileges, or persistence. Its scope is the confidentiality and integrity of requests and resp ...[truncated 371 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the plaintext base URL with an HTTPS endpoint whose certificate is valid and issued for the expected hostname.
- Remove the HTTP endpoint as a fallback; fail closed when a secure endpoint is unavailable.
- Validate
STOCK_API_BASE_URLbefore use:- Require the
httpsscheme. - Restrict the hostname to an explicit allowlist.
- Reject embedded credentials, unexpected ports, URL fragments, and malformed values.
- Require the
- Keep TLS certificate and hostname verification enabled. Do not permit insecure verification bypasses.
- Consider authenticating responses or using signed data if the integrity of financial information is especially important.
- Clearly identify the external data provider and document its trust boundary, availability expectations, and data-validation requirements.
- Validate API response schemas, field types, plausible numeric ranges, and date formats before using returned values in financial analysis.
