T09 · Insecure Skill Coding Practices
- Location
scripts/submit.js:35- Finding
Bearer Token and Submitted Content Can Be Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/submit.js, lines 35 and 54–68
Vulnerability Type: Plaintext transmission of sensitive information
Risk Level: HighVulnerable Code
javascript const API_BASE = config.api_base || 'http://localhost:18999';javascript function apiRequest(method, pathname, body) { return new Promise((resolve, reject) => { const url = new URL(pathname, API_BASE); const isHttps = url.protocol === 'https:'; const transport = isHttps ? https : http; const options = { hostname: url.hostname, port: url.port || (isHttps ? 443 : 80), path: url.pathname, method, headers: { 'Content-Type': 'application/json', ...(TOKEN ? { 'Authorization': `Bearer ${TOKEN}` } : {}), }, };Technical Analysis
The client supports both HTTPS and plaintext HTTP for its configured API endpoint. It does not enforce HTTPS before placing the reusable bearer token in the
Authorizationheader. Submission requests also carry the user-provided title, thoughts, related URL, and display name.Consequently, if
api_baseuses thehttp:scheme, the credentials and request body are transmitted without transport encryption or server authentication. Documentation merely recommends HTTPS rather than making it mandatory. An emptyapi_basealso silently selects the plaintexthttp://localhost:18999fallback.Attack Path
- The user configures an
http://API endpoint, or leavesapi_baseempty and triggers the localhost fallback. - The client constructs a request using Node.js's plaintext
httptransport. - The client includes the bearer token in the
Authorizationheader. - For a submission, the client also sends the title, thoughts, URL, and display name in the request body.
- A network-positioned attacker, an intercepting proxy, or an untrusted service listening on the fallback loc ...[truncated 899 chars]
- The user configures an
- Remediation
View remediation
Remediation Suggestions
- Validate
api_baseduring startup and reject an empty value instead of silently falling back to an HTTP endpoint. - Require the
https:scheme for all non-loopback API destinations. - If plaintext HTTP is needed for local development, permit it only for explicitly validated loopback hosts such as
localhost,127.0.0.1, and::1, and require an explicit development-only opt-in. - Reject unsupported URL schemes and malformed endpoint configurations before constructing any request.
- Do not attach the bearer token to the health-check endpoint unless that endpoint requires authentication.
- Update the documentation to state that HTTPS is mandatory for production rather than merely recommended.
- Consider certificate or public-key pinning in centrally managed deployments where the API identity is fixed.
- Rotate any token that may previously have been transmitted over plaintext HTTP.
- Validate
