T09 · Insecure Skill Coding Practices
- Location
scripts/shortlink.py:185- Finding
API Credential Exposure Through Query Parameters and an Unvalidated Configurable API Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/shortlink.py, lines 26 and 185–186
Vulnerability Type: API credential disclosure and insecure endpoint configuration
Risk Level: MediumVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python request_params = {**params, "appkey": appkey} url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode(request_params)}"Technical Analysis
The script includes the AppKey directly in the URL query string. Query strings are commonly recorded by destination servers, reverse proxies, network-monitoring products, debugging systems, and application telemetry. This creates unnecessary opportunities for credential disclosure.
The risk is compounded by the undocumented
JIKE_API_BASE_URLenvironment variable. Its value is used without validating the URL scheme or destination host. A party capable of influencing the process environment can set this variable to an attacker-controlled host or a plaintext HTTP endpoint. The next API operation will then transmit the AppKey and business parameters to that endpoint.The URL validator applied to user-provided short links does not protect the API endpoint itself. There is no HTTPS requirement, hostname allowlist, or trusted-origin verification for
API_BASE_URL.Attack Path
- An attacker gains the ability to influence the environment used to launch the Skill, such as through a compromised wrapper, deployment configuration, automation job, or shared execution environment.
- The attacker sets
JIKE_API_BASE_URLto an attacker-controlled URL, for examplehttps://attacker.example. - A user or agent invokes
create,restore, orstat. - The script constructs a request to the attacker-controlled endpoint and places the AppKey in the
appkeyquery parameter. - The attacker records the URL, extracts the AppKey, and may als ...[truncated 1030 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the unrestricted
JIKE_API_BASE_URLoverride in production. If endpoint configurability is required, parse the configured URL and enforce:- The
httpsscheme. - An explicit allowlist of trusted hostnames.
- An expected port and normalized origin.
- Rejection of embedded credentials, fragments, and unexpected path components.
- The
- Send the AppKey in a protected request header, such as
Authorizationor a vendor-defined API-key header, rather than in the query string. Coordinate this change with the API provider if the current service only accepts query parameters. - Configure clients and infrastructure not to log authorization headers or sensitive request data.
- Avoid supplying the key through the
--keycommand-line option because process arguments may be visible to other local users or process-monitoring systems. Prefer a protected secret store or tightly controlled environment variable. - Apply least privilege, quotas, and key rotation. Revoke and replace any key suspected of appearing in logs or being sent to an untrusted endpoint.
- Add tests confirming that non-HTTPS endpoints, unapproved hosts, and malformed base URLs are rejected before any network request occurs.
- Remove the unrestricted
