T09 · Insecure Skill Coding Practices
- Location
scripts/generate.js:105- Finding
Internal API Control Bypass and Client Identity Spoofing
- Content
View full analysis
{ ``` ### Technical Analysis The script sends a locally obtained OAuth bearer token to an internal sandbox API at a `v1internal` endpoint. It also supplies client-identification headers that claim the request originates from Antigravity, Google Cloud SDK, and a VS Code Cloud Shell editor integration. The source comment explicitly states that the user-agent version is intended to bypass deprecation checks. This defeats server-side compatibility controls rather than handling deprecation through a supported API migration. The declared client identities also do not truthfully identify this standalone skill. Although the destination is under `googleapis.com` and no credential transmission to an unrelated domain was observed, using an undocumented internal interface makes its authorization requirements, stability, and account-policy behavior difficult to verify. The bearer token grants the endpoint the authority associated with the user's OAuth profile. ### Attack Path 1. A user or agent invokes the image-gen ...[truncated 1317 chars]- Remediation
View remediation
