T09 · Insecure Skill Coding Practices
- Location
src/config.js:18- Finding
Bearer Token and Task Data Transmitted over Plaintext HTTP by Default
- Content
View full analysis
Vulnerability Details
File Location:
src/config.js:18-20(primary location),src/client.js:48-72,cli.js:292-293
Vulnerability Type: Plaintext transmission of credentials and sensitive task data
Risk Level: HighVulnerable Code
js // src/config.js:18-20 // The server's HTTPS certificate is not ready, so HTTP remains the default. const DEFAULT_BASE_URL = 'http://st.aidata366.com';js // src/client.js:48-52 if (!_httpWarned && this.token && this.baseUrl.startsWith('http://')) { _httpWarned = true; process.stderr.write( '[warn] Current service address uses plaintext HTTP; the token will be transmitted in plaintext\n' ); }js // src/client.js:66-72 res = await fetch(this.baseUrl + '/api/v1' + apiPath, { method, headers: { ...(body ? { 'Content-Type': 'application/json' } : {}), ...(this.token ? { Authorization: `Bearer ${this.token}` } : {}), ...headers, },js // cli.js:292-293 const res = await fetch( `${cfg.baseUrl}/api/v1/platform/exports/${encodeURIComponent(info.export_id)}/file`, { headers: { Authorization: `Bearer ${cfg.token}` }, signal: dlCtrl.signal } );Technical Analysis
The built-in service URL uses unencrypted HTTP. Authenticated API calls add the locally stored bearer token to the
Authorizationheader and transmit it to this endpoint. Submission bodies, Xiaohongshu URLs, task results, profile information, and exported CSV data may also traverse the same unencrypted channel.The client detects this condition but only emits a warning to standard error. It neither blocks the request nor requires explicit consent. Therefore, normal use with no custom configuration reaches the unsafe path automatically. Registration and login session requests also inherit the plaintext default.
An on-path attacker can passively read traffic or actively alter requests and responses because HTTP prov ...[truncated 1624 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the default endpoint with a correctly configured HTTPS service using a certificate whose hostname matches the service domain.
- Reject authenticated requests to
http://endpoints instead of merely printing a warning. - If plaintext HTTP is needed for isolated development, require an explicit per-invocation opt-in and restrict it to loopback or otherwise trusted development targets.
- Do not permit persisted production credentials to be sent when plaintext transport is selected.
- Avoid disabling TLS certificate verification in production. Replace self-signed or mismatched certificates rather than relying on
NODE_TLS_REJECT_UNAUTHORIZED=0. - Validate resolved service URLs centrally before registration, login, API requests, and export downloads so every network path enforces the same transport policy.
- After deploying HTTPS, notify users to rotate tokens that may previously have traversed plaintext networks and migrate saved configurations to the secure endpoint.
