T09 · Insecure Skill Coding Practices
- Location
lib/client.py:85- Finding
Unrestricted OpenAI Base URL Can Expose API Credentials and Conversation Data
- Content
View full analysis
Vulnerability Details
File Location:
lib/client.py, lines 85-89 and 253-271
Vulnerability Type: Unvalidated custom API endpoint and sensitive-data transmission
Risk Level: MediumVulnerable Code
python self.client = OpenAI( api_key=config.api_key, base_url=config.base_url )python def load_config(self, path: str) -> None: """Load configuration from file""" config = json.loads(Path(path).read_text()) for name, provider_config in config.get("providers", {}).items(): # Expand environment variables api_key = provider_config.get("api_key", "") if api_key.startswith("${") and api_key.endswith("}"): env_var = api_key[2:-1] api_key = os.environ.get(env_var) self.add_provider(ProviderConfig( name=name, api_key=api_key, model=provider_config.get("model", "gpt-4"), base_url=provider_config.get("base_url"), priority=provider_config.get("priority", 1), timeout=provider_config.get("timeout", 30) ))Technical Analysis
The configuration loader accepts an arbitrary
base_urland passes it to the OpenAI SDK together with the configured API key. The code does not enforce HTTPS, restrict destination hostnames, reject URLs containing embedded credentials, or require explicit approval for nonstandard endpoints.Sending prompts and API credentials over the network is necessary for the declared LLM-adapter functionality. However, permitting an unrestricted endpoint exceeds the minimum privilege required for normal OpenAI access. When a custom endpoint is selected, the SDK can send its authentication header, system prompts, user messages, tool schemas, and other request metadata to that destination.
Exploitation requires the attacker to influence the configuration file or convince the user to load an untr ...[truncated 1329 chars]
- Remediation
View remediation
Remediation Suggestions
- Use the official OpenAI endpoint by default and allow custom endpoints only through an explicit, documented opt-in.
- Require HTTPS for all non-loopback destinations.
- Validate URLs using a structured URL parser and permit only expected schemes.
- Reject URLs containing embedded usernames, passwords, fragments, or malformed host components.
- Maintain an allowlist of trusted provider hostnames where operationally possible.
- Do not automatically reuse an official provider credential with a custom endpoint. Require a separate credential explicitly designated for that endpoint.
- Warn users that configuration files are security-sensitive and must not be loaded from untrusted sources.
- Consider resolving and validating destinations to prevent unintended access to loopback, link-local, metadata-service, and private-network addresses where custom remote endpoints are not required.
- Add automated tests covering HTTP URLs, untrusted hosts, embedded credentials, and environment-variable credential expansion.
