T09 · Insecure Skill Coding Practices
- Location
scripts/pork_query.py:23- Finding
Arbitrary API Endpoint Override Can Disclose the AppKey
- Content
View full analysis
Vulnerability Details
File Location:
scripts/pork_query.py, lines 23 and 132–135
Vulnerability Type: Unvalidated API endpoint override and credential disclosure
Risk Level: MediumVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python params = {"appkey": appkey} if province: params["province"] = province url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode(params)}" try: with urllib.request.urlopen(url, timeout=15) as response: return json.loads(response.read().decode("utf-8"))Technical Analysis
The undocumented
JIKE_API_BASE_URLenvironment variable can replace the trusted API origin with an arbitrary URL. The application does not validate the URL scheme, hostname, port, or destination before appending the AppKey and issuing the request.Because the AppKey is included in the query string, running the script with an attacker-controlled environment can transmit the credential to an attacker-controlled server. Allowing arbitrary destinations also creates limited server-side request forgery behavior, although exploitation requires the attacker to influence the process environment.
Query-string authentication additionally risks credential exposure through URL logging by HTTP clients, proxies, gateways, and destination servers.
Attack Path
- An attacker gains the ability to influence the environment used to launch the Skill, such as through a wrapper, deployment configuration, or compromised process launcher.
- The attacker sets
JIKE_API_BASE_URLto an attacker-controlled endpoint. - A user or Agent invokes
scripts/pork_query.pyaccording to the documented workflow. - The script retrieves the legitimate AppKey from
--key,JIKE_PORK_QUERY_KEY,JIKE_APPKEY, orscripts/.env. - The script appends that AppKey to the attacker-selected URL as the
appkeyquery paramete ...[truncated 776 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
JIKE_API_BASE_URLoverride from production code and use the fixed trusted endpointhttps://api.jikeapi.cn. - If endpoint configurability is required for testing, require an explicit development mode and enforce an allowlist of approved hosts.
- Parse the configured endpoint with
urllib.parse.urlparse()and reject:- Schemes other than HTTPS.
- Hostnames other than explicitly approved API domains.
- Embedded credentials, fragments, and unexpected ports.
- Loopback, link-local, private-network, and metadata-service addresses where they are not explicitly required.
- Disable redirects or validate every redirect destination before forwarding credentials, ensuring credentials are never sent to an untrusted origin.
- Prefer transmitting the AppKey in an authorization header rather than the query string if supported by the API.
- Ensure deployment systems prevent untrusted users or workloads from altering security-sensitive environment variables.
- Rotate the AppKey if the script has previously run in an environment where
JIKE_API_BASE_URLmay have been controlled by an untrusted party.
- Remove the
