T09 · Insecure Skill Coding Practices
- Location
scripts/lib/common.py:48- Finding
Cloud Credentials Can Be Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/lib/common.py:48-63, with the credential-bearing request atscripts/lib/metric_api.py:48-65
Vulnerability Type: Plaintext transmission of cloud credentials
Risk Level: HighComplete Code Snippet
scripts/lib/common.py:48-63:python def sls_endpoint(endpoint, region, project): """Return scheme and service authority for SDK/HTTP transports.""" value = endpoint if endpoint is not None else f"{region}.log.aliyuncs.com" if not isinstance(value, str) or not value.strip() or any(c.isspace() for c in value): raise SkillError("Endpoint must be a SLS service host or HTTP(S) base URL") try: parsed = urlsplit(value if "://" in value else "https://" + value) port = parsed.port except ValueError as exc: raise SkillError("Invalid SLS endpoint") from exc if (parsed.scheme not in {"http", "https"} or not parsed.hostname or parsed.username is not None or parsed.password is not None or parsed.path not in {"", "/"} or parsed.query or parsed.fragment): raise SkillError("Endpoint must be a SLS service host or HTTP(S) base URL without credentials or API path") hostname = parsed.hostnamescripts/lib/metric_api.py:48-65:python password = secret + ("$" + token if token else "") return base64.b64encode((key + ":" + password).encode()).decode() def request(self, source, operation, params): if source["type"] != "metricstore_storeview": raise SkillError("This transport is for SLS metric StoreViews") if operation not in {"query", "query_range", "series", "label/__name__/values"}: raise SkillError("Unsupported metric read operation") project, region, name = source["project"], source["region"], source["name"] if not all(re.fullmatch(r"[a-z0-9][a-z0-9-]*", value) for value in (project, region)): raise SkillError( ...[truncated 2876 chars]- Remediation
View remediation
Remediation Suggestions
-
Change
sls_endpoint()to accept onlyhttpsfor authenticated cloud operations:python if parsed.scheme != "https": raise SkillError("Endpoint must use HTTPS") -
Update
references/datasources/api.mdand all CLI help text to state that endpoint overrides must be HTTPS. -
If plaintext HTTP is required for isolated testing, place it behind an explicit test-only option that is disabled by default and cannot load real credential profiles.
-
Add automated tests confirming that
http://endpoints are rejected before_credentials()is called or any request is sent. -
Consider restricting production endpoints to expected SLS service domains or an explicit administrator-controlled allowlist where deployment requirements permit it.
-
Rotate any credentials that may previously have been used with plaintext HTTP endpoints.
-
