T09 · Insecure Skill Coding Practices
- Location
scripts/translate.py:59- Finding
API Credentials and Document Contents Can Be Sent to Unrestricted or Unencrypted Endpoints
- Content
View full analysis
str: """Call OpenAI-compatible chat completion API with retry on timeout.""" url = f"{base_url.rstrip('/')}/chat/completions" payload_dict = { "model": model, "messages": messages, "temperature": float(os.environ.get("TRANSLATE_TEMPERATURE", "1")), "max_tokens": int(os.environ.get("TRANSLATE_MAX_TOKENS", "4096")), } thinking_mode = os.environ.get("TRANSLATE_THINKING", "auto") if thinking_mode in ("disabled", "auto"): payload_dict["enable_thinking"] = False payload = json.dumps(payload_dict).encode("utf-8") req = urllib.request.Request( url, data=payload, headers={ "Content-Type": "application/json", "Authorization": f"Bearer {api_key}", }, method="POST", ) ``` The destination is read directly from configuration without validation: ```python api_key = os.environ.get("TRANSLATE_API_KEY", "") base_url = os.environ.get("TRANSLATE_BASE_URL", "https://api.siliconflow.cn/v1") model = os.environ.get("TRANSLATE_MODEL", "Qwen/Qwen2.5-7B-Instruct") ``` The setup script accepts an arbitrary endpoint: ```bash --base-url) BASE_URL="$2"; shift 2 ;; ``` The documentation explicitly instructs users or agents to configure custom endpoints: ```bash # Custom endpoint bash ~/.comate/skills/translate-txt/setup.sh --api-key sk-xxx --base-url https://my-api.example.com/v1 --model my-model ``` ### Technical Analysis Sending document text to a remote API is necessary for the declared cloud translation functionality. However, the implementation accepts ...[truncated 2213 chars]- Remediation
View remediation
str: parsed = urlsplit(base_url) if parsed.scheme != "https": raise ValueError("TRANSLATE_BASE_URL must use HTTPS") if not parsed.hostname or parsed.username or parsed.password or parsed.fragment: raise ValueError("Invalid translation API URL") return base_url.rstrip("/") ``` ]]>
