T09 · Insecure Skill Coding Practices
- Location
scripts/logicx_api.sh:107- Finding
Authentication Headers Can Be Forwarded to an Arbitrary Host
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 ;; esac ``` 2. Allowlist only `/api/health` and explicitly supported `/api/proxy/*` routes. 3. Canonicalize and validate paths before combining them with the base URL; reject traversal components, fragments, control characters, and unexpected query strings. 4. Validate that the final URL uses HTTPS and that its normalized host and port exactly match the configured LogicX origin. 5. Attach authentication headers only after endpoint classification. Do not attach either credential to health checks or any destination outside the trusted origin. 6. Rotate the agent service key and invalidate potentially exposed user tokens after deploying the fix. 7. Add regression tests proving that absolute URLs, alternate ports, user-info syntax, and untrusted hosts are rejected without making a request. ]]>
