T09 · Insecure Skill Coding Practices
- Location
SKILL.md:10- Finding
API Credentials and Authenticated Requests Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10–106
Vulnerability Type: Plaintext transmission of sensitive authentication data
Risk Level: HighThe Skill configures its remote API with an unencrypted HTTP URL and instructs users to transmit API keys and authenticated requests to that endpoint.
markdown **Base URL:** `http://54.162.153.8:3000`Representative registration and authenticated request examples include:
bash curl -X POST http://54.162.153.8:3000/api/register \ -H "Content-Type: application/json" \ -d '{"name": "YourAgent", "role": "artist", "walletAddress": "0xYourWallet"}'bash curl http://54.162.153.8:3000/api/rounds/current/state \ -H "X-API-Key: YOUR_API_KEY"bash curl -X POST http://54.162.153.8:3000/api/upload-image \ -H "X-API-Key: YOUR_API_KEY" \ -F "image=@artwork.png"bash curl -X POST http://54.162.153.8:3000/api/bet \ -H "X-API-Key: YOUR_API_KEY" \ -H "Content-Type: application/json" \ -d '{"roundId": 1, "submissionId": 1, "amount": "0.001", "txHash": "0x..."}'Technical Analysis
HTTP does not provide transport encryption, message integrity, or cryptographic server authentication. The registration response containing the API key and all subsequent
X-API-Keyheaders are therefore exposed to any attacker capable of observing or manipulating traffic between the agent and the server.A network-positioned attacker could capture a reusable API key through passive inspection. An active attacker could also modify API responses, uploaded artwork, submission metadata, round state, odds, submission identifiers, or transaction-recording requests. Using a raw IP address over HTTP provides no authenticated hostname or certificate identity through which the client can verify the intended server.
Although the documented blockchain RPC uses HTTPS and a network attacker cannot directly sign transactions ...[truncated 1800 chars]
- Remediation
View remediation
Remediation Suggestions
- Host the API on a stable domain protected by HTTPS with a certificate issued by a trusted certificate authority.
- Replace every occurrence of
http://54.162.153.8:3000with the verified HTTPS origin. - Reject plaintext HTTP connections at the server or network boundary. Do not rely solely on redirects because credentials may already be exposed in the initial HTTP request.
- Rotate all API keys that may previously have been returned or transmitted over plaintext HTTP.
- Use short-lived, revocable authentication tokens with narrowly scoped role permissions rather than indefinitely reusable credentials.
- Avoid logging API keys and redact the
X-API-Keyheader from client, proxy, and server logs. - Before requesting a blockchain signature, independently verify the chain ID, contract address, method arguments, submission identifier, recipient, and transaction value. Do not rely exclusively on data obtained from the off-chain API.
- Consider request signing or application-level integrity protection for security-sensitive API operations as defense in depth, while retaining HTTPS as the mandatory transport.
