T09 · Insecure Skill Coding Practices
- Location
scripts/newapi-banana.py:24- Finding
API Credentials and User Content Are Transmitted Over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/newapi-banana.py:24,scripts/newapi-banana.py:133-159,scripts/newapi-banana.py:260-290,scripts/newapi-banana.py:322-346; also documented inSKILL.md:7,104-105andinstall.md:53-59,94-95
Vulnerability Type: Plaintext transmission of sensitive information
Risk Level: HighVulnerable Code
python # API host DEFAULT_HOST = "http://nen.baynn.com"python def curl_post_json(url: str, payload: dict, headers: dict, timeout: int = 60) -> subprocess.CompletedProcess: with tempfile.NamedTemporaryFile(mode="w", suffix=".json", delete=False) as f: json.dump(payload, f) tmp_path = f.name try: cmd = ["curl", "-s", "-S", "--fail-with-body", "-X", "POST", url, "--max-time", str(timeout), "-d", f"@{tmp_path}"] for k, v in headers.items(): cmd += ["-H", f"{k}: {v}"] return subprocess.run(cmd, capture_output=True, text=True) finally: os.unlink(tmp_path)python if args.image: image_path = Path(args.image) if not image_path.exists(): print(f"Error: image file not found: {args.image}", file=sys.stderr) sys.exit(1) mime_type = mimetypes.guess_type(str(image_path))[0] or "image/png" with open(image_path, "rb") as f: b64_data = base64.b64encode(f.read()).decode() payload["base64"] = f"data:{mime_type};base64,{b64_data}" headers = { "Content-Type": "application/json", "Authorization": f"Bearer {api_key}", } url = f"{DEFAULT_HOST}{endpoint}" result = curl_post_json(url, payload, headers, timeout=120)Technical Analysis
The default API endpoint uses HTTP rather than HTTPS. The script sends the API key in a Bearer authorization header and places user prompts and optional source images in the request body. Base64 encoding of an image only serializes binary content; it d ...[truncated 2344 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the default endpoint with an HTTPS endpoint whose certificate chains to a trusted certificate authority.
- Reject all non-HTTPS API URLs before transmitting credentials or user data.
- Do not provide an insecure HTTP fallback when TLS connection or certificate verification fails.
- Preserve curl's certificate verification and do not add
--insecureor equivalent behavior. - Update
SKILL.md,install.md, and all reference documentation to show only the approved HTTPS endpoint. - Consider certificate or public-key pinning if the deployment model can safely maintain pins.
- Rotate API keys that have already been used through the plaintext endpoint, because their confidentiality cannot be assured.
- Clearly inform users that prompts and source images are sent to the remote provider.
