T09 · Insecure Skill Coding Practices
- Location
scripts/contribute.mjs:3- Finding
Bearer API Key and Learning Data Can Be Exfiltrated Through an Arbitrary Contribution Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/contribute.mjs, lines 3 and 22–29
Vulnerability Type: Unvalidated authenticated endpoint override
Risk Level: HighVulnerable Code
js const BASE_URL = process.env.CLAWLECTIVE_BASE_URL || "https://clawlective.ai";js const res = await fetch(`${BASE_URL}/api/v1/contribute`, { method: "POST", headers: { "Content-Type": "application/json", Authorization: `Bearer ${API_KEY}`, }, body: JSON.stringify({ category, title, summary, body, language, tags }), });Technical Analysis
The undocumented
CLAWLECTIVE_BASE_URLenvironment variable completely controls the origin of the contribution request. The value is not validated against an allowlist and is not required to use HTTPS.The script subsequently attaches
CLAWLECTIVE_API_KEYas a bearer credential and sends the full contribution payload to the selected origin. Consequently, any party capable of influencing the process environment or invocation command can redirect both the credential and submitted data to an attacker-controlled server.Supporting a configurable destination is not necessary for the Skill's declared production functionality, which identifies
https://clawlective.aias the service endpoint. Attaching a production credential to an arbitrary origin therefore exceeds the minimum privilege and trust boundary required by the declared functionality.Attack Path
- An attacker influences the execution environment, wrapper script, CI configuration, shell command, or agent configuration.
- The attacker sets
CLAWLECTIVE_BASE_URLto an attacker-controlled HTTP or HTTPS server. - A user or agent runs
scripts/contribute.mjswith a validCLAWLECTIVE_API_KEY. - The script submits an authenticated request to the attacker-controlled server.
- The attacker records the
Authorizationheader and the contribution body. - The attacker may reuse ...[truncated 748 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the production endpoint override and use a constant authenticated origin:
js const BASE_URL = "https://clawlective.ai"; -
If endpoint configurability is genuinely required for testing, place it behind an explicit development-only mode and reject it during normal production execution.
-
Parse the URL before sending the request and require:
- The
https:protocol. - An exact approved hostname.
- An approved port.
- No embedded username or password.
- The
-
Verify the final request origin immediately before adding the
Authorizationheader. -
Never forward authentication headers across redirects to a different origin. Prefer disabling redirects or validating every redirect target.
-
Document any supported endpoint override and warn that production credentials must never be used with development servers.
-
Rotate any API key that may already have been used while an untrusted
CLAWLECTIVE_BASE_URLwas present.
-
