T09 · Insecure Skill Coding Practices
- Location
search.py:12- Finding
Plaintext HTTP exposes knowledge-base queries and allows search-result tampering
- Content
View full analysis
Vulnerability Details
File Location:
search.py:12-22,search_kb.py:9-21, andSKILL.md:54-58,82-86,103-106
Vulnerability Type: Cleartext transmission of potentially sensitive knowledge-base data
Risk Level: MediumTechnical Analysis
Both search scripts hardcode a remote knowledge-base service using plaintext HTTP. Requests containing the user's query are sent without TLS, and returned document excerpts are accepted without transport-level server authentication or integrity protection.
Relevant code from
search.py:python # Configuration KB_SERVICE_URL = "http://crawdxiaowu.com:3000" def search_knowledge_base(query: str, kb_id: str = "default", top_k: int = 5) -> dict: """Search the knowledge base.""" url = f"{KB_SERVICE_URL}/api/knowledge-bases/{kb_id}/search" data = { "query": query, "top_k": top_k } try: resp = requests.post(url, data=data, timeout=30)Relevant code from
search_kb.py:python KB_SERVICE_URL = "http://crawdxiaowu.com:3000" def main(): query = sys.argv[1] if len(sys.argv) > 1 else "" kb_id = sys.argv[2] if len(sys.argv) > 2 else "test-kb" if not query: print("Usage: python3 search_kb.py 'search content' [knowledge base ID]") sys.exit(1) url = f"{KB_SERVICE_URL}/api/knowledge-bases/{kb_id}/search" try: resp = requests.post(url, data={"query": query, "top_k": 3}, timeout=30)The Skill documentation also directs the Agent to use the same plaintext production service for listing, uploading, searching, and deleting knowledge-base content. For example:
bash curl -X POST http://crawdxiaowu.com:3000/api/knowledge-bases/{kb_id}/files \ -F "file=@/path/to/document.pdf" \ -F "chunk_size=500" \ -F "chunk_overlap=50"bash curl -X POST http://crawdxiaowu.com:3000/api/knowledge-bases/{kb_id}/ ...[truncated 1762 chars]- Remediation
View remediation
Remediation Suggestions
- Replace the hardcoded HTTP endpoint with an HTTPS endpoint protected by a valid certificate.
- Retain certificate verification in
requests; do not setverify=Falseor implement an automatic plaintext fallback. - Reject non-HTTPS production service URLs during configuration validation.
- Update every
curlexample inSKILL.mdto use HTTPS. - Configure the service to redirect or, preferably, refuse plaintext HTTP requests.
- Consider authenticating requests and responses at the application layer where appropriate, while recognizing that authentication does not replace TLS.
- Avoid logging full private queries, document contents, or retrieved excerpts during migration and diagnostics.
- After deploying HTTPS, test search, upload, deletion, and listing operations to ensure no operation silently returns to the plaintext endpoint.
