T09 · Insecure Skill Coding Practices
- Location
skill.js:5- Finding
Unrestricted API Endpoint Can Expose Credentials and User-Provided IP Data
- Content
View full analysis
Vulnerability Details
File Location:
skill.js, lines 5–27
Vulnerability Type: Unvalidated outbound request destination and sensitive-data transmission
Risk Level: HighVulnerable Code
js const API_KEY = env.API_KEY; const API_BASE = env.API_BASE; const MODEL_NAME = env.MODEL_NAME; const prompt = ` 根据以下IP信息,生成${duration}秒抖音/番茄短剧剧本,共${episode_count}集。 要求:节奏快、冲突强、台词短。 输出严格JSON格式: { "scenes": [{"scene":"","role":"","lines":"","action":"","duration":0}], "total_duration": ${duration} }`; const res = await fetch(`${API_BASE}/chat/completions`, { method: "POST", headers: { "Authorization": "Bearer " + API_KEY, "Content-Type": "application/json" }, body: JSON.stringify({ model: MODEL_NAME, messages: [ { role: "user", content: JSON.stringify(ip_info) }, { role: "user", content: prompt } ] }) });Technical Analysis
The Skill requires access to an external language-model service to perform its declared script-generation function. Sending
ip_infoto such a service is therefore functionally relevant. However,API_BASEis accepted directly from the environment and interpolated into the request URL without validating its scheme, hostname, port, or resolved network address.Consequently, the bearer credential in
API_KEYand the complete serializedip_infoobject are sent to whichever destination the environment specifies. The code does not require HTTPS, restrict requests to approved model-provider domains, or reject loopback, private, link-local, and other internal destinations.This exceeds minimum safe privilege because the Skill needs permission to contact a trusted model provider, not arbitrary external or internal hosts. The documentation states that model API configuration is required, but it does not clearly warn users that their supplied IP information is transmitted to a third party.
Attack Path
1 ...[truncated 1725 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace unrestricted
API_BASEconfiguration with a fixed endpoint or an explicit allowlist of approved model-provider origins. - Parse the value with the standard
URLAPI and reject malformed URLs, embedded credentials, unexpected ports, fragments, and query components. - Require
https:and reject plaintext HTTP endpoints. - Resolve and validate destination addresses, rejecting loopback, private, link-local, multicast, and reserved ranges. Revalidate redirects and either disable them or restrict every redirect target to the same allowlist.
- Use separate, provider-scoped credentials with minimal permissions, strict usage limits, and rotation support.
- Do not send the authorization header when the validated destination is not an approved provider.
- Clearly disclose in
SKILL.mdand user-facing documentation thatip_infois transmitted to the selected external model provider. - Minimize transmitted data and allow callers to remove secrets or unnecessary proprietary fields before submission.
- Validate required environment values at startup and fail closed when configuration is missing or unsafe.
- Add automated tests covering HTTP URLs, attacker-controlled domains, internal addresses, malformed URLs, DNS rebinding considerations, and cross-origin redirects.
- Replace unrestricted
