T09 · Insecure Skill Coding Practices
- Location
SKILL.md:62- Finding
Unrestricted API Base URL Can Cause Wallet Credential Disclosure
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:62-74and authenticated request examples atSKILL.md:349-410
Vulnerability Type: Unvalidated security-sensitive endpoint configuration
Risk Level: HighVulnerable Code
text After claiming, your Owner will give you a block like this: == CardZero Agent Configuration == API Key: czapi_a1b2c3d4_e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4 Wallet ID: wallet_7370ee785775 API URL: https://api.cardzero.ai/v1 When you receive this, extract and save: - CARDZERO_API_KEY — the API Key (starts with `czapi_`) - CARDZERO_WALLET_ID — the wallet ID - CARDZERO_API_URL — the API base URLThe configured endpoint is subsequently used together with the bearer credential:
bash curl -X POST "$CARDZERO_API_URL/v1/jobs" \ -H "Authorization: Bearer $CARDZERO_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "providerAddress": "0xabc...", "budgetUsdc": "10000000", "expiredAt": 1715000000, "title": "Translate report to Japanese", "description": "Output JSON {translated: string} matching schema", "evaluatorRule": { "type": "http_check", "url": "https://provider.example.com/output", "expectedStatus": 200 } }'Technical Analysis
The Skill directs the agent to extract both
CARDZERO_API_KEYandCARDZERO_API_URLfrom a configuration block supplied through conversation. It does not require the URL to use HTTPS, verify that its hostname is the official CardZero domain, prohibit embedded credentials, or define redirect restrictions.Authenticated operations then construct request destinations from
CARDZERO_API_URLand attachCARDZERO_API_KEYas a bearer token. Consequently, the party controlling the configuration text can potentially control where the credential is transmitted. This violates the security principle that secret-bearing requests must only be sent to authe ...[truncated 1915 chars]- Remediation
View remediation
Remediation Suggestions
- Pin all credential-bearing requests to the canonical CardZero origin, such as
https://api.cardzero.ai. - Do not accept or update the authenticated API endpoint from ordinary conversational text or pasted configuration blocks.
- If endpoint configurability is required, validate the parsed URL before storing or using it:
- Require HTTPS.
- Compare the normalized hostname against an explicit allowlist.
- Reject IP literals, nonstandard ports, embedded username/password fields, fragments, and malformed URLs.
- Reject lookalike domains and subdomains unless separately allowlisted.
- Normalize the path to prevent duplicate
/v1segments.
- Disable redirects for credential-bearing requests or validate every redirect destination against the same allowlist before forwarding the
Authorizationheader. - Separate endpoint configuration from secret provisioning. Endpoint changes should require an authenticated owner-controlled configuration mechanism and explicit confirmation.
- Never display, log, or transmit the complete API key except in the authorization header sent to the validated CardZero origin.
- Provide credential revocation and rotation guidance. If an untrusted endpoint was previously configured, immediately revoke the affected key, issue a replacement, and review wallet and payment history.
- Apply server-side least-privilege protections, including wallet-bound credentials, transaction and daily limits, anomaly detection, and additional approval for high-risk financial operations.
- Pin all credential-bearing requests to the canonical CardZero origin, such as
