T09 · Insecure Skill Coding Practices
- Location
skill.js:4- Finding
Unrestricted Network Destination Receives API Credentials and User Prompts
- Content
View full analysis
Vulnerability Details
File Location:
skill.js, lines 4–18
Vulnerability Type: Unvalidated credential-bearing outbound request
Risk Level: MediumVulnerable Code
js const API_KEY = env.API_KEY; const API_BASE = env.API_BASE; const MODEL_NAME = env.MODEL_NAME; const res = await fetch(`${API_BASE}/txt2img`, { method: "POST", headers: { "Authorization": "Bearer " + API_KEY, "Content-Type": "application/json" }, body: JSON.stringify({ model: MODEL_NAME, prompt: prompt, negative_prompt: negative_prompt, ratio: "9:16" }) });Technical Analysis
The destination of the outbound request is constructed directly from the environment-controlled
API_BASEvalue without validating its scheme, hostname, port, resolved address, or trust relationship. The request sends theAPI_KEYas a bearer credential and transmits the user-suppliedpromptandnegative_prompt.External network access and transmission of prompts are necessary for the declared remote text-to-image functionality. However, allowing an unrestricted destination is broader than the minimum privilege required. If an attacker can influence runtime configuration, the request can be redirected to an attacker-controlled endpoint or potentially an internal network service. The implementation also does not explicitly require HTTPS or define a restrictive redirect policy, so credential confidentiality depends entirely on external configuration and runtime behavior.
No evidence was found that the Skill intentionally harvests credentials or sends them to a hidden, hard-coded destination.
Attack Path
- An attacker gains the ability to modify or influence the Skill's
API_BASEenvironment value. - The attacker sets
API_BASEto a server under their control or to a reachable internal endpoint. - A user invokes the Skill with a text-to-image prompt.
- The Skill sends a POST request ...[truncated 1099 chars]
- An attacker gains the ability to modify or influence the Skill's
- Remediation
View remediation
Remediation Suggestions
- Replace unrestricted
API_BASEconfiguration with a fixed trusted provider endpoint where operationally possible. - If configurability is required, parse the URL with a standards-compliant URL parser and enforce an explicit allowlist of trusted hostnames and ports.
- Require the
https:scheme and reject plaintext HTTP, embedded URL credentials, unexpected ports, fragments, and malformed URLs. - Prevent SSRF by rejecting loopback, private, link-local, multicast, and other non-public resolved addresses unless a specifically approved private provider is required. Account for DNS rebinding by validating resolved addresses at connection time.
- Disable redirects for credential-bearing requests, or validate every redirect destination against the same scheme, hostname, port, and address restrictions before forwarding the
Authorizationheader. - Use a provider-scoped, least-privilege API key with quota and billing limits, and establish regular key rotation and revocation procedures.
- Validate that
API_KEY,API_BASE, andMODEL_NAMEare present and valid before issuing a request. - Clearly document that prompts and negative prompts are transmitted to an external image-generation provider so users can avoid submitting confidential content.
- Replace unrestricted
