T09 · Insecure Skill Coding Practices
- Location
scripts/mobile_lookup.py:30- Finding
User-Controlled API Endpoint Can Expose the AppKey and Queried Mobile Numbers
- Content
View full analysis
Vulnerability Details
File Location:
scripts/mobile_lookup.py, lines 30 and 203–207
Vulnerability Type: Unvalidated API endpoint override and transmission of sensitive data in URL query parameters
Risk Level: MediumVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python params = urllib.parse.urlencode({"mobile": mobile, "appkey": appkey}) url = f"{API_BASE_URL}{API_PATH}?{params}" try: with urllib.request.urlopen(url, timeout=15) as response: payload = json.loads(response.read().decode("utf-8"))Technical Analysis
The undocumented
JIKE_API_BASE_URLenvironment variable controls the complete API origin. The implementation does not require HTTPS, validate the hostname, or restrict the destination to an allowlist.The request also includes both the private AppKey and the queried mobile number in URL query parameters. Consequently, these values are sent to whichever origin is selected by
JIKE_API_BASE_URL. Query-string credentials may additionally be retained in server, proxy, monitoring, or diagnostic logs.Exploitation requires an attacker to influence the script's environment or the configuration of the process that launches it. No evidence shows that arbitrary remote users can set this variable directly.
Attack Path
- An attacker gains influence over the environment inherited by the Skill process, such as through a compromised launcher, deployment configuration, wrapper script, or orchestration setting.
- The attacker sets
JIKE_API_BASE_URLto an attacker-controlled endpoint, for examplehttp://attacker.example. - A user or Agent invokes the mobile lookup with a legitimate AppKey.
- The script constructs a request to the attacker-controlled origin using
/v1/mobile/query. - The script places the AppKey and mobile number in the query string and sends the request.
- The att ...[truncated 867 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the
JIKE_API_BASE_URLoverride from production builds and use a fixed API endpoint:python API_BASE_URL = "https://api.jikeapi.cn" -
If endpoint configurability is required for testing, parse and strictly validate it:
- Require the
httpsscheme. - Allow only explicitly approved hostnames.
- Reject embedded credentials, fragments, unexpected ports, and nonempty paths.
- Keep test endpoint overrides behind an explicit development-only option.
- Require the
-
Do not place the AppKey in the URL when the API supports a safer credential transport. Prefer an authorization header or a protected POST body. If the upstream API mandates a query parameter, ensure URLs are never logged and redact the
appkeyvalue from exceptions, telemetry, proxy logs, and debugging output. -
Add automated tests verifying that HTTP endpoints, unapproved hosts, malformed URLs, and redirect attempts are rejected.
-
Review redirect handling and either disable redirects or revalidate every redirect destination before forwarding sensitive values.
-
Rotate the AppKey if there is reason to believe the Skill has run with an untrusted
JIKE_API_BASE_URL.
-
