T09 · Insecure Skill Coding Practices
- Location
src/onboard.ts:130- Finding
Unvalidated S3-Compatible Endpoints May Expose Credentials and Uploaded Files
- Content
View full analysis
Vulnerability Details
File Location:
src/onboard.ts:130-140, with the network sink insrc/index.ts:49-57andsrc/index.ts:253-264
Vulnerability Type: Unvalidated network endpoint and insecure transport
Risk Level: MediumVulnerable Code
typescript const endpoint = await prompt('Endpoint URL (e.g., https://minio.example.com): '); const bucketName = await prompt('Bucket name: '); const accessKeyId = await prompt('Access Key ID: '); const secretAccessKey = await prompt('Secret Access Key: '); const region = await prompt('Region (default: us-east-1): ') || 'us-east-1'; config.default = bucketName; config.buckets[bucketName] = { endpoint, access_key_id: accessKeyId, secret_access_key: secretAccessKey, bucket_name: bucketName, region, };The configured endpoint is subsequently used without validation:
typescript function getS3Client(bucketConfig: BucketConfig): S3Client { return new S3Client({ endpoint: bucketConfig.endpoint, region: bucketConfig.region || 'auto', credentials: { accessKeyId: bucketConfig.access_key_id, secretAccessKey: bucketConfig.secret_access_key, }, }); }Uploaded file content is sent through this client:
typescript const s3 = getS3Client(bucketConfig); await s3.send( new PutObjectCommand({ Bucket: bucketConfig.bucket_name, Key: objectKey, Body: fileContent, ContentType: contentType, }) );Technical Analysis
The onboarding process accepts an arbitrary S3-compatible endpoint without parsing the value, enforcing HTTPS, restricting the destination, or warning about insecure transport. Manually supplied configuration is subject to the same issue because
getS3Client()directly trustsbucketConfig.endpoint.The AWS SDK sends credential-derived authorization data with requests. During uploads, it also sends the complete selected file to ...[truncated 1638 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse every configured endpoint with the standard
URLclass and reject malformed values. - Require the
https:protocol by default. - If HTTP support is necessary for local MinIO development, require an explicit opt-in setting and restrict it to loopback or approved private-network destinations.
- Display the normalized destination and require user confirmation before testing a newly configured endpoint.
- Consider an optional endpoint allowlist for managed deployments.
- Revalidate endpoints when loading manually edited configuration rather than relying only on onboarding checks.
- Document that files and signed authorization requests are transmitted to the configured storage operator.
- Parse every configured endpoint with the standard
