T09 · Insecure Skill Coding Practices
- Location
scripts/openclaw_trent/lib/trent_client.py:33- Finding
Configurable API endpoints can disclose the Trent API key to an arbitrary server
- Content
View full analysis
str: return os.environ.get("TRENT_CHAT_API_URL") or _DEFAULT_CHAT_URL def _get_agent_url() -> str: return os.environ.get("TRENT_AGENT_API_URL") or _DEFAULT_AGENT_URL ``` The configurable URL is subsequently used with the Trent API key: ```python headers = { "Authorization": auth_header, "Content-Type": "application/json", "Accept": "text/event-stream", } req = urllib.request.Request( f"{_get_chat_url()}/v1/chat", data=payload, headers=headers, method="POST", ) ``` The same issue affects agent API requests: ```python def _api_request(method: str, endpoint: str, json_data: dict | None = None) -> dict: auth_header = _get_auth_header() url = f"{_get_agent_url()}/v1/trent-agent{endpoint}" payload = json.dumps(json_data).encode() if json_data is not None else None headers: dict[str, str] = { "Authorization": auth_header, "Content-Type": "application/json", } req = urllib.request.Request(url, data=payload, headers=headers, method=method) with urllib.request.urlopen(req, timeout=60) as resp: data = json.loads(resp.read().decode()) ``` ### Technical Analysis Both API base URLs are taken directly from environment variables. Although `_is_trusted_trent_url()` exists elsewhere in the module, it is not applied to `TRENT_CHAT_API_URL` or `TRENT_AGENT_API_URL`. Consequently, a party capable of influencing the audit process's environment can redirect authenticated requests to an arbitrary endpoint. The `Authorization` header containing `TRENT_API_KEY` is attached before the request is sent. The chat request can additionally expose ...[truncated 1525 chars]- Remediation
View remediation
str: url = (os.environ.get(env_name) or default).strip().rstrip("/") if not _is_trusted_trent_url(url): raise RuntimeError(f"Untrusted API endpoint configured in {env_name}") return url ``` ]]>
