T09 · Insecure Skill Coding Practices
- Location
scripts/kie-callback-server.py:8- Finding
Unauthenticated Public Callback Server Allows Forged Payload Storage and Denial of Service
- Content
View full analysis
- Remediation
View remediation
MAX_BODY_SIZE: return self._reply(413, {"ok": False, "error": "payload_too_large"}) ``` 6. Apply socket read timeouts to reduce slow-request denial-of-service exposure. 7. Use UUIDs or nanosecond timestamps for filenames to prevent collisions. 8. Store only necessary headers and redact credentials or tokens. 9. Create files with restrictive permissions and run the service under a dedicated, unprivileged account. 10. Place the service behind a reverse proxy that enforces TLS, rate limits, request-size limits, and source restrictions. ]]>
