T09 · Insecure Skill Coding Practices
- Location
scripts/bank_card_query.py:23- Finding
Configurable API Endpoint Can Exfiltrate API Credentials and Full Card Numbers
- Content
View full analysis
Vulnerability Details
File Location:
scripts/bank_card_query.py, lines 23 and 198–200
Vulnerability Type: Unrestricted destination override for sensitive network requests
Risk Level: HighVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}" try: with urllib.request.urlopen(url, timeout=15) as response: return json.loads(response.read().decode("utf-8"))Technical Analysis
The API destination can be replaced through the undocumented
JIKE_API_BASE_URLenvironment variable. The script does not validate the URL scheme, hostname, port, or resolved destination before sending a request.The generated request includes the AppKey and all business parameters in its query string. For a card query, those parameters include the full card number. Consequently, setting the base URL to an attacker-controlled HTTP or HTTPS endpoint causes the script to disclose both values.
HTTPS is not enforced, and the destination is not restricted to the declared
api.jikeapi.cnservice. The request implementation may also follow redirects, while the code does not verify that the final destination remains within an approved origin.Attack Path
- An attacker, compromised launcher, malicious wrapper, or unsafe runtime configuration sets
JIKE_API_BASE_URLto an attacker-controlled URL. - The user or AI Agent invokes the documented
cardcommand with a bank card number. load_appkey()obtains the configured JikeAPI credential.request_api()appends the credential and complete card number to the attacker-selected URL.urllib.request.urlopen()transmits the request to the attacker-controlled server.- The attacker records and reuses the AppKey and obtains the submitted payment-card data.
Impact
...[truncated 609 chars]
- An attacker, compromised launcher, malicious wrapper, or unsafe runtime configuration sets
- Remediation
View remediation
Remediation Suggestions
- Remove the production endpoint override and use a fixed, reviewed API origin.
- If an override is required for testing, enable it only through an explicit development mode.
- Parse the URL and require the
httpsscheme, the exact approved hostnameapi.jikeapi.cn, and an approved port. - Reject URLs containing user information, fragments, unexpected ports, or unapproved hosts.
- Prevent or validate redirects so that sensitive values cannot be forwarded to another origin.
- Put the AppKey in an authorization header rather than the URL.
- Send the card number in a POST body rather than a query string.
- Ensure application, proxy, and server logs redact credentials and card data.
- Add automated tests confirming that HTTP URLs, lookalike domains, embedded credentials, and cross-origin redirects are rejected.
