T09 · Insecure Skill Coding Practices
- Location
SKILL.md:29- Finding
Spreadsheet REST API Allows Unauthenticated Access by Default
- Content
View full analysis
` | | Content-Type | `application/json` | Base URL can be overridden via environment variable: `OBSIDIAN_SHEET_PLUS_BASE_URL=http://127.0.0.1:3000` ``` ### Technical Analysis The Skill documents that the Obsidian Sheet Plus REST API does not require authentication in its default configuration. This API exposes operations that can read complete workbook data and perform destructive modifications, including clearing cell contents, deleting rows or columns, and overwriting spreadsheet data. Binding the service to `127.0.0.1` reduces exposure to remote hosts but does not establish an authorization boundary. Any local process, compromised application, or other execution context capable of making loopback HTTP requests can invoke the API as the user. The risk would increase substantially if the configurable base address caused the service itself to be exposed on a broader interface. The audit found no evidence of remote payload execution, embedded malicious scripts, persistence mechanisms, dependency attacks, tool spoofing, memory poisoning, or instruction hijacking. ### Attack Path 1. The user starts Obsidian with the Sheet Plus REST API enabled under its default unauthenticated configuration. 2. An untrusted or compromised process running in the same user environment connects to `http://127.0.0.1:3000`. 3. The process calls a read endpoint such as `GET /get_workbook` to retrieve workbook contents without credentials. 4. Alternatively, it submits requests to mutating endpoints such as `/set_sheet_data`, `/delete_rows`, or `/clear_all`. 5. The plugin processes the requests because API-key enf ...[truncated 818 chars]- Remediation
View remediation
