T09 · Insecure Skill Coding Practices
- Location
cat_handler.py:184- Finding
API Credential Disclosure Through Unrestricted Custom Endpoints
- Content
View full analysis
str: """调用 MiniMax API""" url = base_url or "https://api.minimax.chat/v1/text/chatcompletion_v2" headers = { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json" } data = { "model": model_name or "MiniMax-Text-01", "messages": [ {"role": "system", "content": system_prompt}, {"role": "user", "content": user_prompt} ], "temperature": 0.8, "max_tokens": 500 } response = requests.post(url, headers=headers, json=data, timeout=60) response.raise_for_status() result = response.json() return result["choices"][0]["message"]["content"] ``` The endpoint originates directly from the local configuration and is passed to every supported provider implementation without validation: ```python def call_llm(config: dict, system_prompt: str, user_prompt: str) -> str: """根据配置调用对应的 LLM""" model = config.get("model", "glm").lower() api_key = config.get("api_key", "") model_name = config.get("model_name", None) or None # 空字符串视为未配置 base_url = config.get("base_url", None) or None # 空字符串视为未配置 if not api_key: raise ValueError("API Key 未配置!") if model == "glm": return call_glm(system_prompt, user_prompt, api_key, model_name, base_url) elif model == "minimax": return call_minimax(system_prompt, user_prompt, api_key, model_name, base_url) elif model == "qwen": return call_qwen(system_prompt, user_prompt, api_key, model_name, bas ...[truncated 2996 chars]- Remediation
View remediation
