T09 · Insecure Skill Coding Practices
- Location
scripts/molt.py:12- Finding
Configurable API Endpoint Can Expose the Bearer Credential to an Untrusted Server
- Content
View full analysis
Vulnerability Details
File Location:
scripts/molt.py, lines 12–24
Vulnerability Type: Unrestricted API endpoint override and sensitive credential transmission
Risk Level: MediumVulnerable Code
python API_URL = os.environ.get("MOLTOVERFLOW_API_URL", "https://api.moltoverflow.com") API_KEY = os.environ.get("MOLTOVERFLOW_API_KEY", "") def request(method: str, endpoint: str, data: dict = None) -> dict: """Make an API request.""" url = f"{API_URL}{endpoint}" headers = {"Content-Type": "application/json"} if API_KEY: headers["Authorization"] = f"Bearer {API_KEY}" body = json.dumps(data).encode() if data else None req = urllib.request.Request(url, data=body, headers=headers, method=method) try: with urllib.request.urlopen(req, timeout=30) as resp:Technical Analysis
The script allows
MOLTOVERFLOW_API_URLto control the destination of every API request without validating the URL scheme or destination hostname. WhenMOLTOVERFLOW_API_KEYis present, the same request function unconditionally adds it as a bearer token.Consequently, an attacker who can influence the process environment can set the endpoint to an attacker-controlled URL. Invoking any command then transmits the authorization header to that server. Because HTTPS is not enforced, the override can also use plaintext HTTP, exposing credentials and request content to network interception.
Sending the API key to the legitimate MoltOverflow API is necessary for authenticated posting and voting. Permitting the credential to be sent to an arbitrary origin is not necessary for the Skill's declared functionality and exceeds least-privilege network behavior.
Attack Path
- The attacker gains influence over the environment used to launch the Skill, such as through a wrapper, shell configuration, CI configuration, or compromised execution context.
- The attacker sets:
bash export MOLTOVERFLOW_API_URL="https:/
...[truncated 1306 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the endpoint override if custom servers are not required:
python API_URL = "https://api.moltoverflow.com" -
If an override is operationally necessary, validate both the scheme and hostname against an explicit allowlist:
python from urllib.parse import urlparse DEFAULT_API_URL = "https://api.moltoverflow.com" API_URL = os.environ.get("MOLTOVERFLOW_API_URL", DEFAULT_API_URL).rstrip("/") parsed = urlparse(API_URL) if parsed.scheme != "https" or parsed.hostname != "api.moltoverflow.com": raise ValueError("MOLTOVERFLOW_API_URL must use the approved HTTPS endpoint") -
Add the authorization header only after confirming that the final request destination is an approved HTTPS origin. Revalidate redirected destinations or disable cross-origin redirects so credentials cannot be forwarded to another host.
-
Do not attach the bearer token to endpoints that do not require authentication. Separating authenticated and unauthenticated request functions reduces unnecessary credential exposure.
-
Document the endpoint override and its security implications if it is retained. Ensure deployment wrappers, CI jobs, and agent runtimes prevent untrusted parties from modifying the relevant environment variables.
-
Add tests that reject plaintext HTTP, unapproved hosts, crafted URLs, and redirects to unapproved origins.
-
Warn users to remove secrets, proprietary source code, personal data, and access tokens from question and answer content before submission.
-
