T09 · Insecure Skill Coding Practices
- Location
scripts/yufluent_api.py:21- Finding
Bearer Credential and Sensitive Business Data Can Be Transmitted over Plaintext HTTP
- Content
View full analysis
str: base = (base_url or "").strip().rstrip("/") if not base: base = "http://localhost:8080/v1" if base.endswith("/v1"): return base return f"{base}/v1" ``` ```python def _auth_headers(api_key: str) -> dict[str, str]: return { "Authorization": f"Bearer {api_key}", "Accept": "application/json", } ``` ```python def _post_json( url: str, *, api_key: str, body: dict[str, Any] | None = None, timeout: float, ) -> requests.Response: kwargs: dict[str, Any] = { "headers": _json_headers(api_key) if body is not None else _auth_headers(api_key), "timeout": timeout, } if body is not None: kwargs["json"] = body return requests.post(url, **kwargs) ``` ```python root = base_url or os.getenv("TOKENAPI_BASE_URL", "") url = skill_run_url(root, skill_id) try: resp = _post_json(url, api_key=key, body=payload, timeout=timeout) except requests.RequestException as exc: raise YufluentApiError(f"Request failed: {exc}") from exc if _should_fallback_skill_run(resp.status_code): return _run_skill_via_agent_turn( skill_id, payload, api_key=key, base_url=root, timeout=timeout, ) ``` ### Technical Analysis The API root accepts an arbitrary URL supplied through an argument or the `TOKENAPI_BASE_URL` environment variable. No validation requires HTTPS for non-loopback destinations, restricts the destination to an approved Yufluent origin, or rejects embedded credentials and unsupported URL schemes. The client attaches `TOKENAPI_KEY` as an HTT ...[truncated 2128 chars]- Remediation
View remediation
