T09 · Insecure Skill Coding Practices
- Location
scripts/alpaca.sh:24- Finding
Unrestricted API Base URL Can Expose Alpaca Credentials and Trading Data
- Content
View full analysis
Vulnerability Details
File Location:
scripts/alpaca.sh, lines 24–47
Vulnerability Type: Unvalidated credential-bearing request destination
Risk Level: HighVulnerable Code
bash # --- Base URL resolution --- # ALPACA_DATA=1 → market data API; otherwise trading API if [[ "${ALPACA_DATA:-}" == "1" ]]; then BASE_URL="${APCA_DATA_API_BASE_URL:-https://data.alpaca.markets}" else BASE_URL="${APCA_API_BASE_URL:-https://paper-api.alpaca.markets}" fi URL="${BASE_URL}${ENDPOINT}" # --- Build curl args --- CURL_ARGS=( -s -w '\n%{http_code}' -X "$METHOD" -H "APCA-API-KEY-ID: ${APCA_API_KEY_ID}" -H "APCA-API-SECRET-KEY: ${APCA_API_SECRET_KEY}" -H "Accept: application/json" ) if [[ -n "$BODY" ]]; then CURL_ARGS+=(-H "Content-Type: application/json" -d "$BODY") fi # --- Execute --- RESPONSE=$(curl "${CURL_ARGS[@]}" "$URL")Technical Analysis
The wrapper accepts
APCA_API_BASE_URLandAPCA_DATA_API_BASE_URLdirectly from the process environment without validating the URL scheme, hostname, port, or user information. It then attaches the Alpaca API key and secret to every request sent to the resulting URL.Consequently, anyone capable of influencing the wrapper's environment can redirect authenticated requests to an arbitrary server. Non-HTTPS destinations are also accepted, allowing credentials and request content to be transmitted without transport encryption.
Shell command injection is not established here because the URL and other arguments are passed through Bash arrays and quoted expansions. The vulnerability is instead an insecure trust-boundary decision: an untrusted or incorrectly configured destination receives sensitive authentication headers.
Attack Path
- An attacker compromises a launcher, shell profile, automation configuration, or other mechanism capable of setting process environment variables.
- The attacker sets `APCA_API_BASE_ ...[truncated 1268 chars]
- Remediation
View remediation
Remediation Suggestions
-
Strictly allowlist the expected HTTPS origins:
https://paper-api.alpaca.marketshttps://api.alpaca.marketshttps://data.alpaca.markets
-
Parse and validate each configured URL before constructing requests. Reject:
- Any scheme other than HTTPS.
- Hosts outside the explicit allowlist.
- Embedded user information.
- URL fragments.
- Unexpected ports.
- Malformed URLs and ambiguous hostname representations.
-
Enforce endpoint separation:
- Trading requests should only use an approved trading host.
- Market-data requests should only use the approved data host.
-
If custom endpoints are needed for development, require an explicit unsafe-development flag and prevent real Alpaca credentials from being attached to those requests. Use isolated test credentials instead.
-
Fail closed with a clear error before invoking
curlwhenever URL validation fails. -
Add automated tests covering hostile configurations such as HTTP URLs, look-alike domains, user-information syntax, unexpected ports, and attacker-controlled hosts.
-
