T09 · Insecure Skill Coding Practices
- Location
runtime/mcp/src/index.ts:81- Finding
Configurable API endpoint permits credential transmission to arbitrary or plaintext destinations
- Content
View full analysis
{ const rawDomain = (process.env[DOMAIN_ENV] ?? "").trim(); const domainSource: RuntimeConfig["domainSource"] = rawDomain ? "env" : "default"; const domain = normalizeDomain(rawDomain || DEFAULT_DOMAIN); const rawEnv = (process.env[TRADING_ENV] ?? "sim").trim().toLowerCase(); let tradingEnv: RuntimeConfig["tradingEnv"] = "sim"; if (rawEnv === "live") { tradingEnv = "live"; } else if (rawEnv !== "sim") { console.error(`WARN: ${TRADING_ENV}=${rawEnv} 非法,已按 sim 处理(合法值:sim 或 live)`); } const { apiKey, source } = await resolveApiKey(domain); if (!apiKey) { console.error(`WARN: 未配置 ${API_KEY_ENV},交易类工具将返回登录指引;可用 slzq_open_v1_auth_login 完成登录。`); } return { domain, domainSource, apiBase: `${domain}/mobile-api`, apiKey, apiKeySource: source, tradingEnv }; } ``` ```typescript async function openApiFetch( path: string, options: { method?: string; auth: boolean; searchParams?: Record; body?: unknown; } ): Promise<{ ok: boolean; status: number; body: unknown }> { const url = new URL(`${config.apiBase}/open/v1${path.startsWith("/") ? path : `/${path}`}`); if (options.searchParams) { for (const [k, v] of Object.entries(options.searchParams)) { ...[truncated 3893 chars]- Remediation
View remediation
