T09 · Insecure Skill Coding Practices
- Location
scripts/analyze_contract.py:266- Finding
Sensitive Contract Data Can Be Sent to an Arbitrary API Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/analyze_contract.py:203-215, 266-285;README.md:26-27
Vulnerability Type: Unrestricted transmission of confidential data to a configurable endpoint
Risk Level: HighVulnerable Code
python def build_analysis_prompt(text: str, contract_type: str, language: str, tier: str = "FREE") -> str: """Build the AI prompt for contract risk analysis.""" truncated = text[-8000:] if len(text) > 8000 else text # Key terms table is only for STD and above key_terms_instruction = "" if tier in ("STD", "PRO", "MAX"): key_terms_instruction = ''' "key_terms": { "parties": ["Party A", "Party B", ...], "contract_value": "amount if stated, otherwise 'Not specified'", "payment_terms": "payment conditions summary", "duration": "contract duration/term", "termination": "termination conditions", "breach_penalties": "breach of contract penalties", "dispute_resolution": "dispute resolution clause", "governing_law": "applicable law/jurisdiction" }, '''The extracted text is subsequently inserted into the prompt:
python ## Contract Text: {truncated}The prompt is sent to an environment-configurable endpoint:
python def call_ai_analysis(prompt: str, model: str = "minimax/MiniMax-M2") -> dict: """Call AI via OpenAI-compatible API.""" import os api_key = os.environ.get("OPENAI_API_KEY", "") base_url = os.environ.get("OPENAI_API_BASE", "https://api.minimax.chat/v1") if not api_key: # Fallback: try direct OpenAI api_key = os.environ.get("OPENAI_API_KEY_FALLBACK", "") base_url = os.environ.get("OPENAI_API_BASE_FALLBACK", "https://api.openai.com/v1") if not api_key: return {"error": "No API key configured. Set OPENAI_API_KEY or OPENAI_API_KEY_FALLBACK environment variable."} try: ...[truncated 2577 chars]- Remediation
View remediation
Remediation Suggestions
- Permit only an explicit allowlist of reviewed HTTPS API hosts by default.
- Parse and validate the destination URL before creating the client.
- Reject plaintext HTTP, embedded credentials, redirects to unapproved hosts, loopback addresses, link-local addresses, and private-network destinations.
- Require an explicit advanced opt-in before allowing custom endpoints.
- Before transmission, tell the user which host will receive the document and what data will be sent.
- Obtain informed consent before sending contract text to a third party.
- Add configurable redaction for personal identifiers, financial information, signatures, and other sensitive fields.
- Document the selected provider's retention, training, and privacy policies.
- Use a narrowly scoped API credential dedicated to this Skill.
- Avoid following cross-origin redirects that could forward authorization headers or contract content to another host.
