T09 · Insecure Skill Coding Practices
- Location
templates/config.json:4- Finding
Plaintext Transmission and Insecure Storage of API Credentials and Private Video Data
- Content
View full analysis
Vulnerability Details
File Locations:
templates/config.json:4-5SKILL.md:58-61SKILL.md:91-101SKILL.md:143-160SKILL.md:203
Vulnerability Type: Unencrypted transmission of sensitive data and insecure credential storage
Risk Level: HighVulnerable Code
The active configuration directs requests to an unencrypted HTTP endpoint and instructs users to place their App-Key directly in a project file:
json "service_url": "http://47.98.180.113:8083", "Zeelin_App_Key": "Your real AppKey",The documented upload request sends both the App-Key and the complete local video through that HTTP endpoint:
bash curl -X POST "http://47.98.180.113:8083/api/skill/upload" \ -F "appKey=YOUR_APP_KEY" \ -F "file=@/path/to/local/video.mp4"The analysis request also transmits the App-Key without transport encryption:
bash curl -X POST "http://47.98.180.113:8083/api/skill/video" \ -H "Content-Type: application/json" \ -d '{ "appKey": "YOUR_APP_KEY", "videos": [ {"sequence": 1, "oss": "https://jumuai.oss-cn-hangzhou.aliyuncs.com/...video1.mp4"}, {"sequence": 2, "oss": "https://jumuai.oss-cn-hangzhou.aliyuncs.com/...video2.mp4"} ] }'Task status and resulting analysis data are likewise retrieved over HTTP:
bash curl "http://47.98.180.113:8083/api/skill/status/analysis_xxx"Technical Analysis
HTTP provides neither transport confidentiality nor server authentication. Any attacker able to observe or modify traffic between the agent and the configured service can read multipart uploads, JSON request bodies, task identifiers, status responses, and analysis results.
Because the App-Key is placed in form data or a JSON body, it is exposed directly in plaintext while crossing the network. The video file is also uploaded before any HTTPS OSS URL is returned, so the later use of an HTTPS object-storage URL does ...[truncated 2582 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace every HTTP API endpoint with an authenticated HTTPS endpoint under the documented service domain.
- Remove the bare-IP service URL and use a stable domain with a certificate issued by a trusted certificate authority.
- Reject HTTP redirects, TLS certificate errors, hostname mismatches, expired certificates, and attempts to downgrade from HTTPS to HTTP.
- Update all upload, submission, polling, and result-retrieval examples to use HTTPS consistently.
- Store the App-Key in a platform secret store, environment variable, or operating-system credential manager rather than
templates/config.json. - Keep only a clearly named placeholder in the distributed configuration and add real credential files to
.gitignoreor an equivalent exclusion mechanism. - Rotate any App-Key that has previously been transmitted over HTTP or committed to a repository.
- Prefer an authorization header over form or JSON fields if the service supports it, while recognizing that HTTPS remains mandatory regardless of credential placement.
- Require explicit user confirmation before uploading a local video, clearly identifying the external service, destination, and data being transferred.
- Apply short-lived, narrowly scoped credentials and service-side quotas to limit the impact of credential theft.
- Avoid logging request bodies, multipart form fields, authorization data, object URLs containing signatures, or raw analysis responses containing sensitive information.
- Consider certificate pinning or equivalent endpoint verification where the deployment model and certificate-rotation process can support it safely.
