T09 · Insecure Skill Coding Practices
- Location
src/config.js:14- Finding
Bearer Tokens and Account Data Transmitted over Plaintext HTTP by Default
- Content
View full analysis
Vulnerability Details
File Location:
src/config.js:14; data flow tosrc/client.js:48-71
Vulnerability Type: Plaintext transmission of credentials and sensitive data
Risk Level: HighRelevant code:
js // src/config.js:14 const DEFAULT_BASE_URL = 'http://st.aidata366.com';js // src/client.js:48-71 async request(method, apiPath, opts = {}) { const { body, headers = {} } = opts; // Plain HTTP with a token only produces a warning; the request continues. if (!_httpWarned && this.token && this.baseUrl.startsWith('http://')) { _httpWarned = true; process.stderr.write('[warn] Current service address uses plaintext HTTP; token will be transmitted in plaintext\n'); } const ctrl = new AbortController(); const timer = setTimeout(() => ctrl.abort(), REQUEST_TIMEOUT_MS); let res; let payload = null; try { res = await fetch(this.baseUrl + '/api/v1' + apiPath, { method, headers: { ...(body ? { 'Content-Type': 'application/json' } : {}), ...(this.token ? { Authorization: `Bearer ${this.token}` } : {}), ...headers, }, body: body ? JSON.stringify(body) : undefined, signal: ctrl.signal, });The displayed English warning text above is a translation for report readability; the source warning at
src/client.js:54is written in Chinese and explicitly states that the token is transmitted in plaintext.Technical Analysis
The built-in production endpoint uses HTTP rather than HTTPS.
resolveConfig()selects this endpoint whenever the user has not supplied a command-line override, environment override, or saved endpoint.ApiClient.request()then sends API traffic to that endpoint.Authenticated requests place the bearer token in the
Authorizationheader. The same client also performs the unauthenticated session-check exchange that returns the long-lived bearer token in its HTTP ...[truncated 2736 chars]- Remediation
View remediation
Remediation Suggestions
-
Replace the production default with an authenticated HTTPS endpoint and configure valid certificates:
js const DEFAULT_BASE_URL = 'https://st.aidata366.com'; -
Reject plaintext HTTP for all non-loopback destinations, especially for authentication and authenticated API calls. A warning is insufficient:
js const parsed = new URL(this.baseUrl); const loopback = ['localhost', '127.0.0.1', '::1'].includes(parsed.hostname); if (parsed.protocol !== 'https:' && !loopback) { throw new NetworkError('HTTPS is required for non-loopback service endpoints'); } -
Apply the transport check before creating sessions or checking session status, not only when a bearer token is already present. This protects credentials returned in responses as well as credentials sent in requests.
-
Remove the process-wide
NODE_TLS_REJECT_UNAUTHORIZED=0mechanism from production workflows. If development support for private certificates is required, use a narrowly scoped custom certificate authority or per-client TLS configuration and restrict it to explicitly selected development endpoints. -
Update
SKILL.md,API.md, andopenapi.yamlto advertise only the HTTPS production endpoint. Keep HTTP examples limited to explicit loopback development services. -
After deployment of HTTPS enforcement, revoke bearer tokens that may previously have traversed plaintext connections and require affected users to authenticate again.
-
