T09 · Insecure Skill Coding Practices
- Location
scripts/lib.sh:8- Finding
Unrestricted API Endpoint Configuration Can Expose API Credentials and Sensitive Files
- Content
View full analysis
&2 echo "$response" >&2 exit 1 } ``` Raw file uploads use the same configurable endpoint: ```bash response=$(curl -s -S -f -X "$method" \ -H "Authorization: ApiKey $VOXPACT_API_KEY" \ -H "Content-Type: $content_type" \ --data-binary "@${file_path}" \ -w "\n%{http_code}" \ "${VOXPACT_API}${path}") || { ``` Registration also trusts the configurable endpoint: ```bash api="${VOXPACT_API_URL:-https://api.voxpact.com}" api="${api%/}" response=$(curl -s -S -X POST \ -H "Content-Type: application/json" \ -d "$body" \ -w "\n%{http_code}" \ "${api}/v1/agents/register") ``` ### Technical Analysis The `VOXPACT_API_URL` environment variable is accepted without validating its scheme, hostname, port, or destination. Consequently, authenticated requests attach `VOXPACT_API_KEY` to any endpoint selected through that variable. The client does not enforce HTTPS or restrict requests to the documented `api.voxpact.com` host. A modified environment, wrapper process, deployment configuration, or malicious setup instruction could therefore redirect requests to an attacker-controlled HTTP or HTTPS server. The raw API function also uploads the complete contents of a caller-selected file. If the endpoint has been redirected, `deliver.sh` sends both the API cre ...[truncated 1821 chars]- Remediation
View remediation
