T09 · Insecure Skill Coding Practices
- Location
scripts/generate_video.py:58- Finding
Sensitive prompts, images, and API credentials can be transmitted over unencrypted HTTP
- Content
View full analysis
dict: headers = {"Content-Type": "application/json"} if api_key: headers["Authorization"] = f"Bearer {api_key}" return headers def _api_request( url: str, headers: dict, data: bytes | None = None, method: str = "GET", timeout: int = 30 ) -> dict: """Make an HTTP request and return parsed JSON.""" req = urllib.request.Request(url, method=method, headers=headers, data=data) try: with urllib.request.urlopen(req, timeout=timeout) as resp: return json.loads(resp.read().decode("utf-8")) ``` ```python if input_image: img_path = Path(input_image).expanduser() if not img_path.exists(): raise FileNotFoundError(f"Input image not found: {img_path}") b64 = base64.b64encode(img_path.read_bytes()).decode("ascii") body["input_reference"] = b64 data = json.dumps(body).encode("utf-8") headers = _build_headers(api_key) res = _api_request(url, headers, data=data, method="POST", timeout=60) ``` ```python ap.add_argument( "--server", default="http://127.0.0.1:30000", help="SGLang-Diffusion server URL (default: http://127.0.0.1:30000).", ) ``` The documentation explicitly demonstrates using a non-loopback plaintext HTTP destination at `SKILL.md:42`: ```bash python3 {baseDir}/scripts/generate_video.py --prompt "flying through clouds" --server http://192.168.1.100:30000 --out ./my-video.mp4 ``` ### Technical Analysis The script accepts an unrestricted server URL and sends an optional bearer credential through the `Authorization` header. It also sends the user's prompt and, when image-to-video generati ...[truncated 2081 chars]- Remediation
View remediation
