T09 · Insecure Skill Coding Practices
- Location
scripts/http_request_tool.py:36- Finding
Cached platform credentials can be forwarded to an arbitrary URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a plausible API integration helper, but it handles reusable credentials unsafely and can attach them to arbitrary HTTP requests.
Install only after reviewing and preferably fixing credential handling. Use non-production credentials, avoid --url with a configured authenticated platform, avoid --show-cache, rotate any token printed in logs, and restrict use to trusted endpoints until destination allowlisting, redaction, file-permission hardening, and destructive-request confirmation are added.
scripts/http_request_tool.py:36Cached platform credentials can be forwarded to an arbitrary URL
scripts/auth_manager.py:98Authentication secrets and login responses are exposed through standard output
scripts/auth_manager.py:35Reusable credentials are stored in a plaintext cache without enforced restrictive permissions
The documented capability extends beyond API discovery into arbitrary HTTP request execution, auth-header injection, and automatic subprocess-based re-authentication. That is materially broader than a simple OpenAPI discovery tool and can lead to state-changing operations against remote systems, especially when paired with POST/PUT/PATCH/DELETE support and automatic credential reuse.
The documented capability extends beyond API discovery into arbitrary HTTP request execution, auth-header injection, and automatic subprocess-based re-authentication. That is materially broader than a simple OpenAPI discovery tool and can lead to state-changing operations against remote systems, especially when paired with POST/PUT/PATCH/DELETE support and automatic credential reuse.
When a cached token is reused, the script prints the full token to stdout. Because tokens are bearer secrets, anyone who obtains the output can often reuse them directly to authenticate to the target platform until expiry.
The --show-cache code path dumps the entire cached credential structure to stdout with no warning or redaction. This creates a straightforward secret exfiltration channel through terminal output, job logs, and audit pipelines.
The skill advertises and documents shell, network, file read, and file write behaviors but does not declare any explicit tool scope or permission boundaries. In a skill that performs authentication, token caching, and arbitrary API requests, missing scope declarations increases the chance of unintended access, misuse of local files, or execution beyond what a user expects.
The invocation description is extremely broad ('universal' integration for 'any platform'), which encourages over-trust and use in sensitive contexts without clear boundaries. In security terms, overly broad positioning can cause operators to supply credentials, endpoints, and payloads to a tool whose limits and safety assumptions are not explicitly defined.
The skill supports authenticated network requests and destructive HTTP methods but provides no prominent user-facing warning about transmitting data off-host, reusing cached credentials, or modifying remote systems. In this context, lack of warning is especially risky because the tool is designed to work against arbitrary internal or external platforms, making accidental data exposure or unintended state changes more likely.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
print(f"[LOGIN] {url}")
try:
resp = requests.post(url, json=body, headers={"Content-Type": "application/json"}, timeout=TIMEOUT)
except requests.RequestException as e:
sys.exit(f"[ERROR] Login request failed: {e}")
This script exposes bearer tokens and cached authentication material directly to stdout through both the normal cache-hit path and the --show-cache option. In enterprise automation environments, stdout is often captured by shells, CI/CD logs, agent traces, or centralized logging, so printing secrets can lead to credential disclosure and downstream account compromise.
The script stores authentication tokens in a local JSON cache file without warning the user and without any visible protection such as restrictive file permissions or encryption. On multi-user systems or shared workspaces, this can expose reusable credentials to other local users, backup systems, or support tooling.
The help text suggests a benign cache-inspection feature, but the implementation prints the full token cache, including active authentication tokens. This mismatch increases the risk of accidental disclosure because users may invoke the option without realizing it will reveal reusable credentials.
This tool automatically loads cached bearer-style tokens and sends them to either a configured gateway endpoint or any directly supplied --url without enforcing an allowlist or warning the user. In a universal API integration skill, that increases the risk of credential and data exfiltration if a user is induced to target an attacker-controlled host or an untrusted endpoint.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if platform_id:
cmd.extend(["--platform", platform_id])
print("[AUTO] Triggering re-authentication...")
subprocess.run(cmd)
return True
Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.
if params:
kwargs["params"] = params if isinstance(params, dict) else json.loads(params)
resp = getattr(requests, method.lower())(url, **kwargs)
print(f"[{method}] {url}")
print(f"Status: {resp.status_code}")
No suspicious patterns detected.