T09 · Insecure Skill Coding Practices
- Location
src/config.js:20- Finding
Bearer Tokens and Sensitive Collection Data Transmitted over Plaintext HTTP by Default
- Content
View full analysis
Vulnerability Details
File Location:
src/config.js:20-23
Vulnerability Type: Plaintext transmission of authentication credentials and sensitive data
Risk Level: HighVulnerable Code
javascript // Server certificate is not yet configured, so HTTP remains the default. const DEFAULT_BASE_URL = 'http://st.aidata366.com';The default is consumed by
src/client.js:49-70, which sends the bearer token with API requests:javascript if (!_httpWarned && this.token && this.baseUrl.startsWith('http://')) { _httpWarned = true; process.stderr.write('[warn] Current service address uses plaintext HTTP...\n'); } res = await fetch(this.baseUrl + '/api/v1' + apiPath, { method, headers: { ...(body ? { 'Content-Type': 'application/json' } : {}), ...(this.token ? { Authorization: `Bearer ${this.token}` } : {}), ...headers, }, body: body ? JSON.stringify(body) : undefined, signal: ctrl.signal, });CSV downloads repeat this behavior in
cli.js:386-392:javascript const res = await fetch( `${cfg.baseUrl}/api/v1/platform/exports/${encodeURIComponent(info.export_id)}/file`, { headers: { Authorization: `Bearer ${cfg.token}` }, signal: dlCtrl.signal } );Technical Analysis
The built-in service URL uses unencrypted HTTP. Authenticated operations attach the account bearer token to the
Authorizationheader, while submissions and responses can include note URLs, task results, account information, public nicknames, comment text, and IP-location data.The client emits a warning when HTTP is used, and
SKILL.md:54-57discloses the risk, but neither mechanism blocks the request or requires explicit authorization to continue. A warning does not provide confidentiality, integrity, or server authentication.The project permits users to configure HTTPS, so this is not evidence of covert credential theft or malicious intent. Ne ...[truncated 1593 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the default endpoint with a correctly configured HTTPS service using a certificate valid for the service hostname.
- Reject authenticated requests to HTTP endpoints rather than merely printing a warning.
- If HTTP compatibility must temporarily remain, require an explicit per-command opt-in before transmitting credentials and clearly state that it must only be used on a trusted isolated network.
- Apply the same transport-policy check to the direct CSV download path in
cli.js, not only to requests made throughApiClient. - Avoid the process-wide
NODE_TLS_REJECT_UNAUTHORIZED=0bypass. If private certificates must be supported, use a narrowly scoped HTTPS client with an explicitly configured trusted CA. - Rotate tokens that may previously have traversed untrusted plaintext networks after HTTPS enforcement is deployed.
- Add automated tests verifying that bearer-authenticated API calls and export downloads fail closed when the destination uses HTTP.
