T09 · Insecure Skill Coding Practices
- Location
scripts/flow.py:19- Finding
Authentication Token and Workflow Data Can Be Sent to an Untrusted or Unencrypted Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/flow.py:19-20, 40-61, 97-118
Vulnerability Type: Unvalidated network destination and possible plaintext transmission of sensitive data
Risk Level: MediumVulnerable Code
python BASE_URL = os.getenv("MC_JUGGLE_BASE_URL") JUGGLE_TOKEN = os.getenv("MC_JUGGLE_TOKEN")python url = f"{BASE_URL.rstrip('/')}/open/v1/flow/trigger/{flow_version}/{flow_key}" headers = { "Content-Type": "application/json", "Juggle-Token": JUGGLE_TOKEN } request_body = {} if flow_data: request_body["flowData"] = flow_data response = requests.post( url, headers=headers, json=request_body if request_body else None, timeout=30 )python url = f"{BASE_URL.rstrip('/')}/v1/open/flow/getAsyncFlowResult/" params = { "flowInstanceId": flow_instance_id } headers = { "Content-Type": "application/json", "Juggle-Token": JUGGLE_TOKEN } response = requests.get( url, headers=headers, params=params, timeout=30 )Technical Analysis
Sending a Juggle API token and workflow input to the configured Juggle service is necessary for the Skill's declared workflow-triggering functionality. However, the implementation accepts
MC_JUGGLE_BASE_URLwithout validating its scheme, hostname, port, or origin.Consequently, the token is attached to requests made to any destination supplied through that environment variable. An
http://URL is accepted, allowing theJuggle-Token, workflow input, and workflow instance identifiers to traverse the network without transport encryption. A malicious or incorrectly configured URL can instead send these values directly to an attacker-controlled server.The calls also use the default redirect behavior of
requests. BecauseJuggle-Tokenis a custom authentication header rather than the standardAuthorizationheader, applications should ...[truncated 1918 chars]- Remediation
View remediation
Remediation Suggestions
- Parse
MC_JUGGLE_BASE_URLwithurllib.parse.urlparseand reject malformed URLs. - Require the
httpsscheme by default. If HTTP is genuinely required for isolated development, place it behind an explicit opt-in flag and restrict it to loopback or approved private hosts. - Reject URLs containing embedded user information, fragments, unexpected paths, or unapproved ports.
- Support an administrator-defined hostname allowlist or pin the expected Juggle origin during credential setup. For self-hosted deployments, store the approved origin alongside the token rather than accepting a destination independently for each execution.
- Disable automatic redirects with
allow_redirects=False. If redirects are required, follow them manually only after confirming that the scheme, hostname, and port match the approved origin. - Use a dedicated
requests.Sessionwith centrally enforced TLS, redirect, proxy, and timeout policies. - Provide a configurable CA bundle for private deployments instead of encouraging TLS verification to be disabled.
- Scope Juggle tokens to only the workflow operations and workflow keys required by the Skill, and rotate any token suspected of having been sent to an untrusted destination.
- Warn users before transmitting fields identified as credentials or secrets, and avoid collecting such fields unless the selected workflow strictly requires them.
- Parse
