T09 · Insecure Skill Coding Practices
- Location
skills/smyx_common/scripts/util.py:548- Finding
Sensitive Child Health Data and Authentication Tokens Transmitted Over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Locations:
skills/smyx_common/scripts/config.yaml:15skills/smyx_common/scripts/config-dev.yaml:2-4skills/smyx_common/scripts/util.py:548-561skills/smyx_common/scripts/util.py:572-646skills/smyx_analysis/scripts/skill.py:113-139
Vulnerability Type: Plaintext transmission of sensitive medical media, identity data, and authentication credentials
Risk Level: HighVulnerable Code
The packaged configuration activates the development environment:
yaml env: devThat environment replaces the nominal HTTPS API services with plaintext HTTP endpoints:
yaml ApiEnum: base-url-open-api: "http://192.168.1.234:9601/smyx-open-api" base-url-open-h5: "http://192.168.1.234:4100" base-url-health: "http://192.168.1.234:7070/jeecg-boot-xzgz"Automatic account creation sends the resolved internal identifier in both the
openIdandmobilefields:python def _get_or_create_user(username): _url = ApiEnum.BASE_URL_HEALTH + "/sys/phoneLogin" open_id = username _data = { "silent": 1, "register": 1, "openId": open_id, "mobile": username, "source": ConstantEnum.DEFAULT__SKILL_HUB_NAME } try: _response = requests.post(_url, json=_data) if _response.status_code == 200: _response_json = _response.json() if _response_json and _response_json.get("success"): return _response_json and _response_json.get("result") except Exception as _e: CommonUtil.trace_exception_stack(_e) return {}The common request layer attaches authentication tokens and identity metadata to outgoing requests. It also permits request data to be moved into URL parameters:
python if not url.startswith("https://") and not url.startswith("http://"): url = cls.BASE_URL + url headers['App-Id'] = ConstantEnum.APP__ID headers.setdefault("X-Access-Token", ApiEnum.TOKEN) headers.setdefault("X-A ...[truncated 5627 chars]- Remediation
View remediation
Remediation Suggestions
-
Require HTTPS for every service endpoint
- Reject URLs that do not begin with
https://. - Do not permit plaintext HTTP as a silent fallback.
- Fail closed with a clear security error if an insecure endpoint is configured.
- Reject URLs that do not begin with
-
Ship production-safe configuration
- Remove
env: devfrom release artifacts or change it to a production environment that uses HTTPS exclusively. - Keep private development endpoints in a separate, unshipped configuration.
- Add startup validation that prevents development configuration from being used in production.
- Remove
-
Maintain certificate validation
- Keep TLS certificate verification enabled.
- Do not introduce
verify=False. - Where appropriate, restrict trusted certificate authorities or use certificate pinning for high-sensitivity health-data endpoints.
-
Keep sensitive data out of URLs
- Remove
dataAsParamsfor requests containing identity, health, tenant, or authentication information. - Transmit necessary fields in an encrypted request body.
- Ensure tokens are sent only in headers over HTTPS.
- Remove
-
Minimize identity collection
- Do not duplicate the same identifier as
openId,mobile, andpnaUserName. - Do not label a generated internal identifier as a mobile number.
- Send only the minimum pseudonymous identifier required by the server.
- Do not duplicate the same identifier as
-
Protect child health media
- Obtain explicit informed consent before uploading child video.
- Clearly disclose the service operator, destination, retention period, deletion process, and whether media is used for model training.
- Provide a deletion mechanism for uploaded media and generated reports.
- Avoid retaining media locally longer than necessary.
-
Protect and rotate credentials
- Rotate any tokens that may have been transmitted through the HTTP development endpoints.
- Store tokens using operating-system credential storage or an encrypted secret store rat ...[truncated 668 chars]
-
