T09 · Insecure Skill Coding Practices
- Location
scripts/idiom_query.py:23- Finding
API Credential Exposure Through Query Strings and an Unrestricted Endpoint Override
- Content
View full analysis
Vulnerability Details
File Location:
scripts/idiom_query.py:23andscripts/idiom_query.py:238
Vulnerability Type: API credential exposure and unrestricted destination configuration
Risk Level: MediumVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"Technical Analysis
The script appends the AppKey directly to the request URL as an
appkeyquery parameter. URLs are commonly recorded by destination servers, reverse proxies, monitoring systems, network diagnostics, and application logs. Consequently, the credential may be retained in more locations than necessary and become accessible to operators or systems that can inspect those records.The destination is also controlled by the undocumented
JIKE_API_BASE_URLenvironment variable without scheme or hostname validation. The code accepts arbitrary hosts and non-TLS schemes. An attacker who can influence the process environment or a compromised launcher can redirect requests to an attacker-controlled endpoint. Because the AppKey and user-provided idiom query are included in the URL, the destination receives both values.This does not grant local privilege escalation by itself, and exploitation of the endpoint override requires influence over the execution environment. Nevertheless, the combination creates a direct credential-exfiltration path.
Attack Path
- An attacker compromises or controls the wrapper, launcher, CI job, shell profile, or other configuration that starts the Skill.
- The attacker sets
JIKE_API_BASE_URLto an endpoint under their control, potentially using unencrypted HTTP. - A user invokes a documented command while a valid AppKey is supplied through the CLI, environment, or local
.envfile. request_api()constructs a URL cont ...[truncated 881 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
JIKE_API_BASE_URLoverride if custom endpoints are not a required feature. - If endpoint customization is required, parse the URL and enforce:
- The
httpsscheme. - An explicit allowlist of trusted hostnames.
- Expected ports and path constraints.
- Rejection of embedded credentials, fragments, loopback addresses, link-local addresses, and untrusted redirects.
- The
- Prefer sending the AppKey in an API-supported authentication header rather than in the query string.
- If the upstream API only accepts a query parameter, ensure clients, proxies, servers, and monitoring systems redact
appkeyfrom logs. - Disable or strictly validate redirects so a trusted endpoint cannot redirect authenticated requests to an untrusted host.
- Document every supported environment variable and its security implications.
- Rotate any key suspected of appearing in logs or having been sent to an untrusted endpoint.
- Add automated tests confirming that non-HTTPS and non-allowlisted API base URLs are rejected before any network request occurs.
- Remove the
