T09 · Insecure Skill Coding Practices
- Location
scripts/carbosilex_client.py:114- Finding
API Key Disclosure Through an Unrestricted API Destination
- Content
View full analysis
dict[str, str]: """Build request headers with optional authentication.""" headers = { "Content-Type": "application/json", "Accept": "application/json", } if self.api_key: headers["X-API-Key"] = self.api_key return headers ``` For example, the key-bearing header is used when listing public jobs: ```python with httpx.Client(timeout=30) as client: resp = client.get(self._url("/jobs/"), params=params, headers=self._headers) ``` ### Technical Analysis The client accepts an arbitrary `base_url` from either the `CARBOSILEX_API_URL` environment variable or the `CarbosilexClient` constructor. It does not validate the normalized hostname, URL scheme, port, embedded user information, or whether the destination belongs to CarboSilex137. At the same time, `_headers` adds the `CARBOSILEX_API_KEY` to every request whenever a key is available. This includes operations documented as public, such as job listing, job details, the job feed, and the platform health check. These operations do not require authentication and therefore should not receive the credential. This design means that configuration influence over `CARBOSILEX_API_URL` can become a creden ...[truncated 2355 chars]- Remediation
View remediation
