T09 · Insecure Skill Coding Practices
- Location
scripts/generate.js:3- Finding
API credential and user prompt can be redirected to an attacker-controlled endpoint
- Content
View full analysis
[instrumental(true/false)]"); process.exit(1); } async function generate() { try { const res = await fetch(`${API_BASE}/api/skill/generate_music`, { method: "POST", headers: { "Content-Type": "application/json", Authorization: `Bearer ${API_KEY}`, }, body: JSON.stringify({ model: "Fi", custom: true, instrumental: instrumental, prompt: prompt, title: "", style: "", advance: { vocal_gender: "", ai_lyrics: true } }), }); ``` ### Technical Analysis The script takes the API destination from the `MBM_API_BASE` environment variable and unconditionally sends the configured `apiKey` to that destination in an `Authorization` header. It does not validate the URL scheme or hostname before transmitting the credential. The endpoint override is not documented as necessary for the Skill's declared production functionality. Normal operation only requires access to `https://api.makebestmusic.com`. Consequently, allowing an arbitrary override expands the trust boundary beyond the minimum privileges required. The request body also contains the user's music prompt. If the environment ...[truncated 1395 chars]- Remediation
View remediation
