T09 · Insecure Skill Coding Practices
- Location
src/config.js:17- Finding
Bearer Credentials and Sensitive Task Data Transmitted over Plaintext HTTP by Default
- Content
View full analysis
Vulnerability Details
File Location:
src/config.js:17, with authenticated request sinks atsrc/client.js:48-70andcli.js:310-313
Vulnerability Type: Plaintext transmission of credentials and sensitive data
Risk Level: HighComplete Code Snippets
src/config.js:17:js const DEFAULT_BASE_URL = 'http://st.aidata366.com';src/client.js:48-70:js // Plaintext HTTP with a token only produces a warning; the request proceeds. if (!_httpWarned && this.token && this.baseUrl.startsWith('http://')) { _httpWarned = true; process.stderr.write('[warn] Current service address uses plaintext HTTP; the token will be transmitted in plaintext\n'); } const ctrl = new AbortController(); const timer = setTimeout(() => ctrl.abort(), REQUEST_TIMEOUT_MS); let res; let payload = null; try { res = await fetch(this.baseUrl + '/api/v1' + apiPath, { method, headers: { ...(body ? { 'Content-Type': 'application/json' } : {}), ...(this.token ? { Authorization: `Bearer ${this.token}` } : {}), ...headers, }, body: body ? JSON.stringify(body) : undefined, signal: ctrl.signal, });cli.js:310-313:js const res = await fetch(`${cfg.baseUrl}/api/v1/platform/exports/${encodeURIComponent(info.export_id)}/file`, { headers: { Authorization: `Bearer ${cfg.token}` }, signal: dlCtrl.signal });Technical Analysis
The built-in service endpoint uses unencrypted HTTP. The API client attaches the account bearer token to authenticated requests regardless of whether the transport is encrypted. Registration and login session operations, profile and quota queries, submitted Xiaohongshu links, task results, and CSV exports consequently use plaintext transport under the default configuration.
The warning at
src/client.js:48-52is informational only. It neither prevents the request nor requires an explicit per-request acknowledgm ...[truncated 2123 chars]- Remediation
View remediation
Remediation Suggestions
- Deploy a correctly configured HTTPS endpoint and change
DEFAULT_BASE_URLto itshttps://URL. - Reject authenticated API calls, login or registration session checks, and export downloads when
baseUrluses HTTP. - If plaintext HTTP is required for local development, permit it only through an explicit development-only option and restrict it to loopback addresses by default.
- Do not rely on a stderr warning as a security control; fail closed before attaching bearer credentials to an insecure request.
- Keep TLS certificate verification enabled. Avoid carrying
insecure: trueinto normal production use, and require explicit acknowledgment for any diagnostic exception. - After migrating to HTTPS, revoke or rotate tokens that may previously have traversed plaintext networks.
- Consider minimizing sensitive URL retention and logging because submitted links contain
xsec_tokenvalues.
- Deploy a correctly configured HTTPS endpoint and change
