T09 · Insecure Skill Coding Practices
- Location
SKILL.md:13- Finding
Authentication Credential and Customer PII Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 13 and 26–66
Vulnerability Type: Plaintext transmission of sensitive information
Risk Level: HighVulnerable Code
markdown **Base URL:** `http://39.108.114.224:9059`bash # Customer profile search curl -s -X POST -H "Content-Type: application/json" \ "http://39.108.114.224:9059/skill/search_customer_profile" \ -d '{ "user_key": "<user_key>", "q_keywords": "hotel hospitality resort", "organization_locations": ["Japan"], "person_titles": ["Business Development", "Partnership Manager"], "person_seniorities": ["manager", "director", "head"], "contact_email_status": ["verified", "likely to engage"], "per_page": 10, "page": 1 }' # Bulk customer import curl -s -X POST -H "Content-Type: application/json" \ "http://39.108.114.224:9059/skill/batch_import_customer" \ -d '{ "user_key": "<user_key>", "customers": [ { "name": "Hilton Tokyo", "contact_name": "John Smith", "contact_email": "john@hiltontokyo.com", "contact_phone": "80012345", "contact_phone_prefix": "+81", "country_code": "JP", "address": "Tokyo, Japan", "remark": "Business Development | Hospitality" } ] }'Technical Analysis
The Skill configures both API operations to use unencrypted HTTP. HTTP does not provide transport confidentiality, message integrity, or authenticated server identity. Consequently, every request can expose the
user_keycredential and customer personal information—including names, email addresses, telephone numbers, and physical addresses—to an attacker with visibility into the network path.An on-path attacker could also modify requests or responses without detection. This could alter search results, inject fraudulent customer records, replace CRM import data, or c ...[truncated 1954 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace every
http://39.108.114.224:9059endpoint with anhttps://endpoint protected by a valid TLS certificate. - Use a DNS hostname whose identity can be validated against the certificate rather than relying on a bare IP address.
- Configure clients to verify the certificate chain and hostname. Do not disable TLS verification or accept self-signed certificates without a securely managed private trust anchor.
- Reject redirects from HTTPS to HTTP and prevent protocol downgrade behavior.
- Rotate all
user_keyvalues that may previously have been transmitted over HTTP. - Store authentication credentials in an operating-system secret store or another protected credential mechanism. If a file remains necessary, enforce owner-only permissions and avoid exposing its contents in logs or error messages.
- Apply short credential lifetimes, revocation support, rate limits, and least-privilege scopes to reduce the value of a captured key.
- Minimize customer data transmitted and displayed to only the fields required for the requested operation.
- Add request timeouts, explicit status handling, response validation, and audit logging that redacts credentials and personal data.
- Document the external data processor and ensure appropriate user notice, consent, retention controls, and privacy safeguards are in place before transmitting customer information.
- Replace every
