T09 · Insecure Skill Coding Practices
- Location
scripts/calendar_tao_query.py:23- Finding
Unvalidated API Base URL Allows AppKey Exfiltration
- Content
View full analysis
Vulnerability Details
File Location:
scripts/calendar_tao_query.py, lines 23 and 111
Vulnerability Type: Unvalidated endpoint override and credential disclosure
Risk Level: HighVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode({'date': date_value, 'appkey': appkey})}"Technical Analysis
The undocumented
JIKE_API_BASE_URLenvironment variable can override the intended API origin with an arbitrary URL. The value is used without validating its scheme, hostname, port, or trust relationship.The application subsequently places the AppKey in the URL query string and sends the request to the configured origin. Consequently, a malicious or compromised launcher that can inject environment variables can redirect the request to an attacker-controlled endpoint. Supplying an
http://endpoint would also permit plaintext transmission.Query-string credentials may additionally be retained by HTTP server logs, reverse proxies, monitoring systems, and other URL-processing infrastructure.
Attack Path
- An attacker compromises or controls the process launcher, service configuration, CI job, wrapper script, or other mechanism that defines the skill's environment.
- The attacker sets
JIKE_API_BASE_URLto an attacker-controlled endpoint, such ashttps://attacker.example. - A legitimate AppKey remains available through
JIKE_CALENDAR_TAO_QUERY_KEY,JIKE_APPKEY,--key, orscripts/.env. - The user or agent invokes the documented calendar query.
- The script constructs a URL under the attacker-controlled origin and embeds both
dateandappkeyin its query string. - The attacker's server receives and records the AppKey and queried date.
Impact Assessment
The attacker can obtain the API credential used by the skill and then perform request ...[truncated 438 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
JIKE_API_BASE_URLoverride if custom API endpoints are not a required feature. - If configurability is required, parse the URL and enforce an explicit allowlist:
- Require the
httpsscheme. - Require the exact approved hostname, such as
api.jikeapi.cn. - Reject embedded user information, fragments, unexpected ports, and deceptive subdomains.
- Require the
- Construct URLs from a fixed trusted origin rather than concatenating an unrestricted environment value.
- Prefer transmitting credentials in an authorization header instead of the query string if the API supports it.
- Ensure launch configurations and environment-variable sources are writable only by trusted principals.
- Add tests confirming that HTTP URLs, unrelated hosts, deceptive subdomains, and malformed endpoint values are rejected.
- Remove the
