T09 · Insecure Skill Coding Practices
- Location
scripts/validate.py:77- Finding
Provider API Credentials Can Be Transmitted to Arbitrary or Plaintext Endpoints
- Content
View full analysis
Vulnerability Details
File Location:
scripts/validate.py:77-78,scripts/validate.py:111-121,scripts/validate.py:145-146,scripts/validate.py:218-220;scripts/test_provider.py:64-68,scripts/test_provider.py:95-108,scripts/test_provider.py:134-139,scripts/test_provider.py:218-220
Vulnerability Type: Unrestricted credential destination and server-side request forgery
Risk Level: HighVulnerable Code
From
scripts/validate.py:python def test_openai(api_key: str, base_url: Optional[str], model: Optional[str]) -> Tuple[bool, str]: """Test OpenAI API.""" url = (base_url or 'https://api.openai.com/v1') + '/models' req = urllib.request.Request(url, headers={'Authorization': f'Bearer {api_key}'})python def test_anthropic(api_key: str, base_url: Optional[str], model: Optional[str]) -> Tuple[bool, str]: """Test Anthropic API.""" url = (base_url or 'https://api.anthropic.com') + '/v1/messages' test_model = model or 'claude-3-5-sonnet-20241022' data = json.dumps({ 'model': test_model, 'max_tokens': 1, 'messages': [{'role': 'user', 'content': 'Hi'}] }).encode() req = urllib.request.Request( url, data=data, headers={ 'Content-Type': 'application/json', 'x-api-key': api_key, 'anthropic-version': '2023-06-01' } )python def test_provider(name: str, settings: Dict) -> Tuple[bool, str]: """Test a provider.""" api_key = settings.get('apiKey', '') base_url = settings.get('baseUrl') model = settings.get('model')From
scripts/test_provider.py:python def test_openai_api(api_key: str, base_url: str = None, model: str = None) -> Tuple[bool, str]: """Test OpenAI API connectivity and model.""" url = (base_url or 'https://api.openai.com/v1') + '/models' req = urllib.request.Reques ...[truncated 3129 chars]- Remediation
View remediation
Remediation Suggestions
- Normalize URLs before use and permit only
httpsfor credential-bearing provider requests. - Maintain provider-specific hostname allowlists, such as the official OpenAI and Anthropic API hosts.
- Treat custom endpoints as a separate, explicit feature requiring informed user confirmation.
- Reject URLs containing user information, fragments, unsupported ports, loopback addresses, link-local addresses, and private network addresses unless local access is explicitly required.
- Resolve destination hostnames and validate all resulting IP addresses to reduce DNS rebinding risk.
- Disable automatic redirects or validate every redirect target. Never forward an API key when the scheme, hostname, or port changes.
- Build authentication headers only after the final destination has passed validation.
- Add tests covering plaintext URLs, attacker-controlled domains, cross-origin redirects, loopback targets, private addresses, and link-local metadata endpoints.
- Normalize URLs before use and permit only
