T09 · Insecure Skill Coding Practices
- Location
scripts/easydoc_parse.py:143- Finding
Unrestricted Base URL Override Can Exfiltrate Documents and API Credentials
- Content
View full analysis
Dict: url = f"{base_url.rstrip('/')}{submit_path}" payload, boundary = encode_multipart( fields=[("mode", mode)], files=[(file_field, file_path) for file_path in file_paths], ) headers = { "api-key": api_key, "Content-Type": f"multipart/form-data; boundary={boundary}", } return http_json("POST", url, headers=headers, body=payload, timeout=timeout) ``` ```python base_url = args.base_url.strip() or platform_config["base_url"] ``` The polling path is affected by the same destination override: ```python path = result_path_template.format(task_id=task_id) url = f"{base_url.rstrip('/')}{path}" headers = {"api-key": api_key} return http_json("GET", url, headers=headers, timeout=timeout, retries=retries) ``` ### Technical Analysis The Skill legitimately needs network access to upload user-selected documents to the declared EasyDoc services. Its documented official destinations are: - `https://api.easylink-ai.com` - `https://api.easydoc.sh` However, the `--base-url` option accepts an arbitrary string without validating its URL scheme or hostname. The resulting URL receives both: 1. The API key in the `api-key` HTTP header. 2. The complete contents and filename of every selected document in a multipart request. Consequently, the process does not enforce that sensitive data is transmitted only to the declared EasyDoc services. An HTTP URL ...[truncated 2250 chars]- Remediation
View remediation
