T09 · Insecure Skill Coding Practices
- Location
skills/smyx_common/scripts/config.yaml:15- Finding
Sensitive Infant Footage and Authentication Credentials Transmitted over Cleartext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
skills/smyx_common/scripts/config.yaml:15,skills/smyx_common/scripts/config.py:43-50,skills/smyx_common/scripts/config-dev.yaml:1-7,skills/smyx_analysis/scripts/skill.py:108-138,skills/smyx_common/scripts/util.py:543-561, 610-646
Vulnerability Type: Cleartext transmission of sensitive media, identity data, and authentication credentials
Risk Level: HighVulnerable Code
skills/smyx_common/scripts/config.yaml:15:yaml env: devskills/smyx_common/scripts/config.py:43-50:python config_path = os.path.join(cls_dirpath, "config.yaml") config = YamlUtil.load(config_path) cls.init(config) env = config.get("env") if env: env_config_path = os.path.join(cls_dirpath, f"config-{env}.yaml") env_config = YamlUtil.load(env_config_path) cls.init(env_config)skills/smyx_common/scripts/config-dev.yaml:1-7:yaml ApiEnum: base-url-open-api: "http://192.168.1.234:9601/smyx-open-api" base-url-open-h5: "http://192.168.1.234:4100" base-url-health: "http://192.168.1.234:7070/jeecg-boot-xzgz" ConstantEnum: is-debug: trueskills/smyx_analysis/scripts/skill.py:108-138:python files = None if not input_path: raise ValueError("必须提供本地视频路径(--input)或网络视频URL(--url)") if (input_path.startswith("http://") or input_path.startswith("https://")): params.update({ "videoUrl": input_path }) else: _validate_file(input_path) # 自动检测 MIME 类型 mime_type, _ = mimetypes.guess_type(input_path) if mime_type is None: mime_type = 'application/octet-stream' # 读取文件内容 with open(input_path, 'rb') as f: file_content = f.read() files = { 'file': (os.path.basename(input_path), file_content, mime_type) } open_id = argss.pop('open_id', None) response = self.analysis( params=params, files=files )skills/smyx_common/scripts/util.py:543-561:python def _get_or_create_user(username): _url = ApiE ...[truncated 4037 chars]- Remediation
View remediation
Remediation Suggestions
- Change the release configuration to use the production environment and HTTPS-only endpoints.
- Remove
env: devandconfig-dev.yamlfrom production distributions, or require an explicit development-only opt-in. - Reject API and authentication URLs whose scheme is not
https. - Do not permit silent fallback from HTTPS to HTTP.
- Retain normal TLS certificate and hostname verification; do not introduce
verify=False. - Rotate all authentication tokens that may have traversed the cleartext endpoints.
- Clearly disclose that infant footage is uploaded to an external service and obtain explicit user consent before transmission.
- Minimize transmitted metadata and avoid sending identity fields that are not required for analysis.
- Add automated tests that fail the build when active release endpoints use HTTP.
- Consider certificate pinning or equivalent endpoint trust controls where the deployment model supports secure lifecycle management.
