T09 · Insecure Skill Coding Practices
- Location
scripts/hy_translate.py:153- Finding
Arbitrary API endpoints receive credentials and complete translation content
- Content
View full analysis
str: """Call translation API via OpenAI-compatible interface.""" cfg = API_BACKENDS[backend] url = url or cfg["url"] model = model or cfg["default_model"] if not url: raise ValueError( f"No endpoint URL provided for backend '{backend}'. " f"Pass --url on the command line." ) headers = { "Content-Type": "application/json", "Authorization": f"Bearer {api_key}", } payload = { "model": model, "messages": [{"role": "user", "content": prompt}], "temperature": 0.1, "max_tokens": 4096, "stream": False, } for attempt in range(MAX_RETRIES): try: resp = requests.post(url, headers=headers, json=payload, timeout=REQUEST_TIMEOUT) ``` The associated Skill instructions explicitly permit a custom Tencent Cloud URL and persistence of that URL: ```markdown - **`tencent_cloud`**: Uses the Hy Translation API provided by Tencent Cloud. The endpoint URL has a built-in default (`https://api.hunyuan.cloud.tencent.com/v1/chat/completions`) — the user does not need to provide it. However, the user may optionally supply a different URL, which will be stored in memory and used going forward. ``` ### Technical Analysis The script sends both the Bearer API key and the complete translation prompt to the value supplied through `--url`. No validation requires HTTPS, verifies the expected hostname, constrains Tencent credentials to the official Tencent endpoint, or warns when the endpoint changes. This network behavior is necessary ...[truncated 1682 chars]- Remediation
View remediation
