T09 · Insecure Skill Coding Practices
- Location
scripts/cookbook_query.py:23- Finding
Environment-Controlled API Endpoint Can Disclose the AppKey
- Content
View full analysis
Vulnerability Details
File Location:
scripts/cookbook_query.py, lines 23 and 194–196
Vulnerability Type: Unvalidated destination for sensitive API credentials
Risk Level: MediumVulnerable Code
python API_BASE_URL = os.environ.get( "JIKE_API_BASE_URL", "https://api.jikeapi.cn" ).rstrip("/")python url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}" try: with urllib.request.urlopen(url, timeout=15) as response: return json.loads(response.read().decode("utf-8"))Technical Analysis
The destination used for API requests can be overridden through the undocumented
JIKE_API_BASE_URLenvironment variable. The value is accepted without validating its scheme or hostname.Every request appends the AppKey to the URL query string. Consequently, a process or deployment configuration capable of influencing
JIKE_API_BASE_URLcan redirect the request—and the credential—to an arbitrary server. The implementation also does not require HTTPS, so an override using anhttp://URL can transmit the credential without transport encryption.The attacker-controlled server can return syntactically valid JSON that the script will process and present as cookbook data. This creates both a credential-confidentiality risk and a response-integrity risk.
Attack Path
- An attacker or compromised deployment component modifies the process environment and sets
JIKE_API_BASE_URLto an attacker-controlled endpoint, such ashttps://attacker.example. - A legitimate AppKey remains configured through
JIKE_COOKBOOK_QUERY_KEY,JIKE_APPKEY, the--keyoption, or the local.envfile. - A user or agent invokes any supported command, such as
search,detail,ingredient, orrandom. - The script constructs a URL against the attacker-controlled base URL and adds the AppKey as the
appkeyquery parameter. - `urllib. ...[truncated 839 chars]
- An attacker or compromised deployment component modifies the process environment and sets
- Remediation
View remediation
Remediation Suggestions
- Remove the
JIKE_API_BASE_URLoverride from production builds if custom endpoints are not an explicit requirement. - If endpoint customization is required, parse the configured URL and enforce:
- The
httpsscheme. - An exact allowlist of approved hostnames, preferably only
api.jikeapi.cn. - No embedded username or password.
- No unexpected port, fragment, or path components.
- The
- Construct requests from a fixed trusted origin rather than concatenating an unrestricted environment value.
- Prefer transmitting the AppKey in a supported authorization header instead of the query string. This reduces exposure through URL logs, monitoring systems, and error reports.
- Reject invalid endpoint configuration before loading or transmitting the AppKey.
- Add automated tests confirming that HTTP URLs, unapproved domains, deceptive subdomains, and URLs containing user information are rejected.
- Document any intentionally supported endpoint override and its security constraints in
SKILL.md.
- Remove the
