T09 · Insecure Skill Coding Practices
- Location
scripts/emr_qc_impl.py:57- Finding
Caller-Controlled LLM Endpoint Can Expose API Credentials and Medical Records
- Content
View full analysis
str: payload = {"model": model, "messages": messages, "temperature": 0} resp = _http_post(url, payload, headers, timeout=timeout) ``` ### Technical Analysis The command-line `--base` argument is accepted without validating its scheme, hostname, port, resolved address, or relationship to the intended HiVoice service. The resulting URL receives an HTTP request containing: - The API credential in the `Authorization: Bearer ...` header. - The model request payload, including EMR-derived physical-examination and diagnosis data. Consequently, anyone able to influence invocation arguments can redirect the request to an attacker-controlled service. Permitting arbitrary destinations can also enable server-side requests to internal or link-local services from environments where the Skill has network access. No restriction guarantees HTTPS or prevents redirects to an untrusted destination. A non-HTTPS endpoint could additionally expose credentials and medical information to network interception. ### Attac ...[truncated 1387 chars]- Remediation
View remediation
