T09 · Insecure Skill Coding Practices
- Location
scripts/analyze.sh:25- Finding
Bearer Token May Be Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/analyze.sh:25-26, 55-57, 94-95, 176; related insecure configuration guidance atSKILL.md:178-179
Vulnerability Type: Sensitive credential transmission over an unencrypted connection
Risk Level: HighComplete Code Snippets
The documentation explicitly permits an HTTP API endpoint while configuring a bearer token:
bash export TRADINGAGENTS_API_URL="http://your-server:8000" export TRADINGAGENTS_TOKEN="ta-sk-your_key_here"The script accepts that endpoint without validating its scheme:
bash API_URL="${TRADINGAGENTS_API_URL:-https://api.510168.xyz}" TOKEN="${TRADINGAGENTS_TOKEN:?Please set the TRADINGAGENTS_TOKEN environment variable}"The token is then attached to submission, polling, and result requests:
bash resp=$(curl -s -w "\n%{http_code}" -X POST "${API_URL}/v1/analyze" \ -H "Authorization: Bearer ${TOKEN}" \ -H "Content-Type: application/json" \ -d "$payload")bash resp=$(curl -s "${API_URL}/v1/jobs/${job_id}" \ -H "Authorization: Bearer ${TOKEN}")bash resp=$(curl -s -w "\n%{http_code}" "${API_URL}/v1/jobs/${job_id}/result" \ -H "Authorization: Bearer ${TOKEN}")The batch polling path has the same behavior:
bash resp=$(curl -s "${API_URL}/v1/jobs/${jid}" -H "Authorization: Bearer ${TOKEN}")Technical Analysis
The configurable API URL is used directly without requiring HTTPS. Although the default hosted endpoint uses HTTPS, the documented self-hosting configuration explicitly uses
http://. Every API operation suppliesTRADINGAGENTS_TOKENin theAuthorizationheader.When the endpoint is HTTP, transport encryption and server authentication are absent. Any party able to observe or intercept traffic—such as an untrusted Wi-Fi operator, compromised router, malicious proxy, or adjacent network attacker—can obtain the bearer token. Because a bearer credential proves authorization solely through possession, the captured val ...[truncated 1747 chars]
- Remediation
View remediation
Remediation Suggestions
- Validate
TRADINGAGENTS_API_URLbefore making any request and reject non-HTTPS schemes by default. - If plaintext HTTP is needed for local development, permit it only for loopback hosts such as
127.0.0.1,localhost, and::1. - Require an explicit, prominently named opt-in such as
ALLOW_INSECURE_HTTP_FOR_LOCAL_DEVELOPMENT=1for any exceptional HTTP use. - Replace the documentation's
http://your-server:8000example with an HTTPS endpoint and provide TLS termination guidance for self-hosted deployments. - Configure curl with secure transport options such as
--proto '=https' --tlsv1.2for non-loopback endpoints. - Do not introduce
--insecureor disable certificate verification. - Use narrowly scoped, short-lived tokens where supported, and provide clear token rotation and revocation procedures.
- Add automated tests verifying that remote HTTP endpoints are rejected before the bearer token is transmitted.
- Validate
