T09 · Insecure Skill Coding Practices
- Location
index.js:2- Finding
Unvalidated Ticker Input Can Alter the Outbound Request Path
- Content
View full analysis
Vulnerability Details
File Location:
index.js:2
Vulnerability Type: Unvalidated input in an outbound URL
Risk Level: LowVulnerable Code:
javascript const url = `https://x402-money-machine-api-ssyopros.zocomputer.io/api/whale/${ticker.toUpperCase()}`;Technical Analysis
The caller-controlled
tickervalue is converted to uppercase and directly interpolated into an outbound URL without strict validation or percent-encoding. Uppercasing does not neutralize URL control characters such as/,?, or#.An attacker can therefore provide a ticker containing path or query delimiters to alter the request sent to the fixed third-party origin. For example, a value such as
BTC?mode=othercould append an unintended query string, while path separators could select a route other than the intended ticker resource.The hostname and scheme remain fixed, so this does not provide unrestricted server-side request forgery to arbitrary origins. No authentication credentials are attached by the current implementation.
Attack Path
- An attacker or untrusted caller invokes
executewith a craftedticker. - The value is uppercased but is neither validated nor encoded.
- URL delimiters in the value modify the path, query, or fragment of the outbound request.
- The skill sends a request to an unintended route on the configured external service.
- Unless the service responds with HTTP 402, its JSON response is returned unchanged to the caller.
Impact Assessment
Exploitation is limited to manipulating requests made to the hard-coded
x402-money-machine-api-ssyopros.zocomputer.ioorigin. An attacker may reach unintended routes or alter request parameters exposed by that service. The reviewed code does not grant local privileges, expose credentials, or permit requests to attacker-selected hosts, which limits the severity.- An attacker or untrusted caller invokes
- Remediation
View remediation
Remediation Suggestions
- Require
tickerto be a string before using it. - Enforce a strict allowlist appropriate for supported asset symbols, including a conservative length limit.
- Apply
encodeURIComponentafter validation before inserting the value into a URL path segment. - Prefer the
URLAPI to construct outbound URLs safely. - Reject invalid input before making any network request.
Example:
javascript export async function run({ ticker = "BTC" } = {}) { if (typeof ticker !== "string") { throw new TypeError("ticker must be a string"); } const normalizedTicker = ticker.toUpperCase(); if (!/^[A-Z0-9.-]{1,15}$/.test(normalizedTicker)) { throw new Error("Invalid ticker format"); } const url = `https://x402-money-machine-api-ssyopros.zocomputer.io/api/whale/${encodeURIComponent(normalizedTicker)}`; const response = await fetch(url); // Continue with validated response handling. }- Require
