T09 · Insecure Skill Coding Practices
- Location
scripts/data_agent/sse_client.py:303- Finding
Unrestricted Custom Endpoint Can Receive Signed Authentication Material and Sensitive Analysis Data
- Content
View full analysis
Vulnerability Details
File Location:
scripts/data_agent/sse_client.py:303-323
Related Configuration Source:scripts/data_agent/config.py:47-58, 94-103
Vulnerability Type: Unvalidated credential-bearing network endpoint
Risk Level: HighVulnerable Code
python # scripts/data_agent/config.py:94-103 return cls( api_key=os.environ.get("DATA_AGENT_API_KEY") or None, region=os.environ.get("DATA_AGENT_REGION", "cn-hangzhou"), endpoint=os.environ.get("DATA_AGENT_ENDPOINT"), timeout=int(os.environ.get("DATA_AGENT_TIMEOUT", "300")), max_retry=int(os.environ.get("DATA_AGENT_MAX_RETRY", "3")), poll_interval=int(os.environ.get("DATA_AGENT_POLL_INTERVAL", "2")), max_poll_count=int(os.environ.get("DATA_AGENT_MAX_POLL_COUNT", "60")), workspace_id=os.environ.get("DATA_AGENT_WORKSPACE_ID"), )python # scripts/data_agent/sse_client.py:303-323 host = self._config.endpoint headers = AliyunSignerV3.sign( access_key_id, access_key_secret, "POST", host, "GetChatContent", params, security_token=security_token if security_token else None, ) headers["User-Agent"] = "AlibabaCloud-Agent-Skills/alibabacloud-data-agent-skill" query_params = {"Action": "GetChatContent", "Version": "2025-04-14", **params} query_string = "&".join( f"{quote(k, safe='')}={quote(str(v), safe='')}" for k, v in sorted(query_params.items()) ) url = f"{self._base_url}/?{query_string}" with requests.post( url, stream=True, timeout=timeout, headers=headers, ) as response:Technical Analysis
DATA_AGENT_ENDPOINTis accepted without validating its hostname, domain suffix, path, or expected Alibaba Cloud service identity. In AK/SK mode, the endpoint is used as the signing host and request destination.The outbound headers contain an ACS authorization signature, the access key identifier, and ...[truncated 1973 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse configured endpoints with
urllib.parse.urlsplitrather than treating them as arbitrary strings. - Permit only documented Alibaba Cloud domains, such as exact service-specific hosts under
aliyuncs.com. - Validate that the endpoint corresponds to the configured region and expected service.
- Reject embedded user information, query strings, fragments, unexpected paths, IP literals, and non-HTTPS schemes.
- Require a separate, explicit development-only option before allowing custom endpoints.
- Do not send cloud signatures or STS tokens to a custom endpoint unless it has been independently authenticated.
- Revalidate endpoint configuration immediately before constructing each credential-bearing request.
- Recommend narrowly scoped custom RAM policies instead of broad DMS full-access policies.
- Parse configured endpoints with
