T09 · Insecure Skill Coding Practices
- Location
scripts/field_extractor.py:253- Finding
Unrestricted API endpoint can receive sensitive document content and bearer credentials
- Content
View full analysis
Vulnerability Details
File Location:
scripts/field_extractor.py:253-279
Vulnerability Type: Unrestricted sensitive-data transmission and server-side request forgery exposure
Risk Level: HighVulnerable Code
python api_base = api_base or DEFAULT_API_BASE model = model or DEFAULT_MODEL # Build messages system_prompt = SYSTEM_PROMPTS.get(doc_type, SYSTEM_PROMPTS["generic"]) user_prompt = build_user_prompt(doc_type, custom_fields).format(text=text[:8000]) # Truncate to 8k chars messages = [ {"role": "system", "content": system_prompt}, {"role": "user", "content": user_prompt}, ] # Call API endpoint = f"{api_base.rstrip('/')}/chat/completions" headers = { "Content-Type": "application/json", "Authorization": f"Bearer {api_key}", } payload = { "model": model, "messages": messages, "temperature": temperature, "max_tokens": 2048, } try: response = requests.post(endpoint, headers=headers, json=payload, timeout=timeout)Technical Analysis
The AI-assisted extraction feature legitimately requires sending document text to a model provider. However, the caller-controlled
api_baseis used without validating its URL scheme, hostname, resolved IP address, or trust relationship with the supplied credential.The resulting request transmits both:
- Up to 8,000 characters of PDF-derived content, potentially including identity numbers, bank account details, addresses, contractual terms, invoices, and other confidential information.
- The API key in an
Authorization: Bearerheader.
An endpoint using plaintext HTTP can expose both values to network interception. A malicious endpoint can directly collect them. Depending on network accessibility, loopback, private, link-local, and cloud metadata destinations may also be reachable, creating server-side request forgery exposure.
A timeout limits request duration but does not restrict de ...[truncated 1572 chars]
- Remediation
View remediation
Remediation Suggestions
- Require HTTPS and reject plaintext HTTP endpoints.
- Use a provider-specific allowlist for model API hostnames by default.
- Make custom endpoints an explicit opt-in accompanied by a warning that document content and credentials will be transmitted.
- Resolve the destination hostname and reject loopback, private, link-local, multicast, and cloud metadata address ranges unless an administrator explicitly authorizes them.
- Revalidate every redirect destination or disable redirects for API requests.
- Bind each API credential to its expected provider hostname and refuse to forward it to a different host.
- Display or log the destination hostname before transmission without logging the API key or document content.
- Require explicit consent before transmitting sensitive document classes such as identity documents and bank statements.
- Consider optional local extraction or redaction of sensitive fields before remote processing.
- Add tests covering HTTP rejection, malicious redirects, DNS resolution to private addresses, metadata endpoints, and provider/credential mismatches.
