T09 · Insecure Skill Coding Practices
- Location
scripts/calendar_holiday_query.py:26- Finding
API Credential Exposure Through Query Strings and an Unrestricted Configurable Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/calendar_holiday_query.py, lines 26, 81, and 136-138
Vulnerability Type: API credential exposure and unrestricted credential destination
Risk Level: MediumVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python parser.add_argument("--key", dest="cli_key", help="Temporarily provide the Jike Data AppKey")python url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}" try: with urllib.request.urlopen(url, timeout=15) as response: return json.loads(response.read().decode("utf-8"))Technical Analysis
The application inserts the AppKey directly into the URL query string. Query-string credentials can be recorded in web server logs, reverse-proxy logs, network diagnostics, monitoring systems, and URL telemetry. Supplying the key with
--keycan additionally expose it through shell history and local process listings.The API destination is controlled by the undocumented
JIKE_API_BASE_URLenvironment variable without scheme or hostname validation. Consequently, any party capable of influencing the process environment can direct an otherwise legitimate holiday query to an arbitrary endpoint. Because the AppKey is appended beforeurlopen()sends the request, that endpoint receives the credential. A value using plain HTTP could also transmit the key without transport encryption.This does not independently let a remote attacker modify the environment. Exploitation requires influence over the execution environment, service configuration, wrapper script, CI job, container configuration, or command invocation.
Attack Path
- The attacker gains the ability to set or influence environment variables for the Skill process, such as through a compromised wrapper, CI configuration, container deployment, or service ...[truncated 1209 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove runtime control of the API origin unless it is strictly required. Prefer a fixed constant for
https://api.jikeapi.cn. -
If endpoint configurability is necessary, parse the URL and enforce:
- The
httpsscheme. - An explicit allowlist of trusted hostnames.
- An expected port.
- No embedded user information.
- No unexpected path prefix.
- The
-
Send the credential in an authorization header supported by the provider rather than in the query string, for example:
python request = urllib.request.Request(url) request.add_header("Authorization", f"Bearer {appkey}") with urllib.request.urlopen(request, timeout=15) as response: ...If the provider only accepts an
appkeyquery parameter, request header-based authentication support and ensure URLs are redacted from all logs and diagnostics in the interim. -
Remove the
--keyoption for normal use and rely on protected environment or secret-management facilities. If it must remain for debugging, prominently warn that command-line secrets can appear in process listings and shell history. -
Ensure
.envfiles containing credentials are excluded from source control and readable only by the intended account. -
Disable or carefully validate redirects for authenticated requests so credentials cannot be forwarded to an unexpected origin.
-
Rotate any AppKey that may already have appeared in command history, process telemetry, proxy logs, or server logs.
-
