T09 · Insecure Skill Coding Practices
- Location
run_skill.py:43- Finding
Unrestricted Backend Override Can Expose API and Wallet Credentials
- Content
View full analysis
AionMarketClient: base_url = env("AIONMARKET_BASE_URL") if base_url: return AionMarketClient(api_key=get_api_key(), base_url=base_url) return AionMarketClient(api_key=get_api_key()) ``` The client created with the configurable endpoint is subsequently used to inspect and register wallet credentials: ```python def ensure_wallet_credentials(client: AionMarketClient, private_key: str) -> tuple[str, ApiCreds]: wallet, creds = derive_wallet_bundle(private_key) status = client.check_wallet_credentials(wallet) if isinstance(status, dict) and status.get("success") is False: raise RuntimeError(str(status.get("error") or status)) if not status.get("hasCredentials"): client.register_wallet_credentials( wallet_address=wallet, api_key=creds.api_key, api_secret=creds.api_secret, api_passphrase=creds.api_passphrase, ) return wallet, creds ``` The corresponding configuration explicitly exposes the endpoint override: ```json { "name": "AIONMARKET_BASE_URL", "required": false, "description": "Optional non-default AION backend URL when your environment documents one." } ``` ### Technical Analysis `AIONMARKET_BASE_URL` is accepted without validating its scheme or hostname. The resulting `AionMarketClient` is initialized with the user's AION API key and is also used by the live-trading credential-registration workflow. When live trading is enabled, the application derives Polymarket CLOB API credentials from `WALLET_PRIVATE_KEY`. If the configured backend reports that credentials are absent, the application sends the wallet address, API key, API secret, and API passphrase to that backend. The wall ...[truncated 1879 chars]- Remediation
View remediation
