T09 · Insecure Skill Coding Practices
- Location
modeio_guardrail/cli/safety.py:52- Finding
Unrestricted Backend Override Permits Sensitive Data Exfiltration and Forged Safety Decisions
- Content
View full analysis
Vulnerability Details
File Location:
modeio_guardrail/cli/safety.py:52-53, 111-118
Vulnerability Type: Unrestricted external endpoint configuration and cleartext transport
Risk Level: MediumVulnerable Code:
python # Backend API URL, overridable via SAFETY_API_URL environment variable URL = os.environ.get("SAFETY_API_URL", "https://safety-cf.modeio.ai/api/cf/safety")python def detect_safety(instruction: str, context: str = None, target: str = None) -> dict: """ Call the Modeio safety backend and return the full response JSON. Response includes: approved, risk_level, risk_types, concerns, recommendation, etc. """ payload = {"instruction": instruction} if context: payload["context"] = context if target: payload["target"] = target resp = _post_with_retry(URL, json_payload=payload) return resp.json()The HTTP request is issued without endpoint validation at
modeio_guardrail/cli/safety.py:88:python resp = requests.post(url, json=json_payload, timeout=timeout)Technical Analysis
The
SAFETY_API_URLenvironment variable can replace the trusted safety backend with an arbitrary URL. The implementation does not enforce HTTPS, validate the hostname, restrict ports, or maintain an allowlist of trusted endpoints. The test attests/test_safety_contract.py:92-96confirms that a plain HTTP URL is accepted:python result = self._run_cli( ["--input", "Delete all log files in production", "--json"], env={"SAFETY_API_URL": "http://127.0.0.1:9"}, )Requests may contain instruction text, operational context, file paths, database identifiers, service names, URLs, data-sensitivity classifications, and change-control information. If an attacker can control the process environment, these values can be redirected to an attacker-controlled server or exposed through unencrypted HTTP.
The clie ...[truncated 2187 chars]
- Remediation
View remediation
Remediation Suggestions
- Require the configured URL to use
httpsand reject cleartext HTTP or other schemes. - Allowlist the production safety backend hostname and expected port. If custom endpoints are needed for development, require an explicit development-only option.
- Reject URLs containing embedded credentials, fragments, unexpected ports, or untrusted redirect destinations.
- Disable redirects or validate every redirect target against the same scheme and hostname policy.
- Consider certificate or public-key pinning where the operational environment supports it.
- Validate backend responses against a strict schema. Require
approvedto be a Boolean andrisk_levelto be one of the documented values; reject unknown, missing, or malformed decision fields. - Minimize transmitted data and redact secrets, credentials, tokens, sensitive query parameters, and unnecessary resource details before submission.
- Document that endpoint overrides are security-sensitive and ensure service managers, CI systems, and wrappers prevent untrusted users from modifying the Skill's environment.
- Add tests proving that non-HTTPS URLs, unapproved hosts, malformed responses, and redirects to unapproved hosts are rejected.
- Require the configured URL to use
