T09 · Insecure Skill Coding Practices
- Location
craft-helper.sh:7- Finding
Capability-Bearing Craft API URLs Embedded in Public Project Files
- Content
View full analysis
Vulnerability Details
File Location:
craft-helper.sh:7-9; duplicated inSKILL.md:22-30andSKILL.md:148-152
Vulnerability Type: Hardcoded sensitive access configuration
Risk Level: HighVulnerable Code
craft-helper.sh:7-9:bash # API URLs WAVEDEPTH_API="https://connect.craft.do/links/5VruASgpXo0/api/v1" PERSONAL_API="https://connect.craft.do/links/HHRuPxZZTJ6/api/v1"SKILL.md:22-30:bash ### wavedepth Space (Business) ```bash ~/clawd/skills/craft-cli/craft config set-api https://connect.craft.do/links/5VruASgpXo0/api/v1Personal Space
bash ~/clawd/skills/craft-cli/craft config set-api https://connect.craft.do/links/HHRuPxZZTJ6/api/v1text ### Technical Analysis The project embeds unique link-based API endpoints associated with named business and personal Craft spaces. The documentation treats the API URL as the authentication configuration and states that an invalid or unauthorized API URL results in an authentication failure. This indicates that possession of a valid URL may convey access authority rather than merely identifying a public service endpoint. Storing such capability-bearing URLs directly in scripts and documentation exposes them to every person or system that can read the project, including repository users, package recipients, logs, backups, and source-history mirrors. The documented CLI supports reading and mutating operations, including document listing, retrieval, creation, update, and deletion. ### Attack Path 1. An attacker obtains a copy of the project or reads its repository history. 2. The attacker extracts either hardcoded Craft API URL from `craft-helper.sh` or `SKILL.md`. 3. The attacker installs or otherwise obtains the compatible Craft CLI. 4. The attacker configures the CLI using: ```bash craft config set-api <extracted-api-url> ``` 5. The attacker tests access using `craft list`, `craft sea ...[truncated 751 chars]- Remediation
View remediation
Remediation Suggestions
- Revoke both exposed Craft links immediately and generate replacements.
- Remove all capability-bearing URLs from scripts, documentation, examples, release artifacts, and repository history.
- Require users to supply API URLs through protected runtime configuration, such as an environment variable, operating-system credential store, or secret-management service.
- Add the local configuration file containing the URL to
.gitignoreand ensure it has restrictive filesystem permissions. - Replace real endpoints in documentation with obvious placeholders such as
https://connect.craft.do/links/YOUR_LINK/api/v1. - Review Craft access logs for use of the exposed links and investigate unexpected document reads or mutations.
- Restrict each replacement credential to the minimum required space and operations, and implement periodic rotation.
- Add automated secret scanning to CI and pre-commit workflows to prevent similar links from being committed again.
