T09 · Insecure Skill Coding Practices
- Location
scripts/run.py:219- Finding
Caller-Controlled LLM Endpoint Exposes Bearer Credentials and Medical Data
- Content
View full analysis
str: url = f"{base.rstrip('/')}/chat/completions" headers = {"Authorization": f"Bearer {appkey}"} if appkey else {} payload = { "model": model, "messages": [{"role": "user", "content": prompt}], "temperature": 0, } response = _http_post(url, payload, headers, timeout=timeout) ``` The destination is exposed directly as a command-line option: ```python parser.add_argument("--base", default=DEFAULT_LLM_BASE, help=f"Internal LLM base URL (default: {DEFAULT_LLM_BASE}).") ``` The caller-controlled value is passed to the network request without validation: ```python response = run( payload, base=args.base, model=args.model, appkey=args.appkey, timeout=args.timeout, ) ``` ### Technical Analysis The `--base` argument accepts an unrestricted URL. `call_llm()` appends `/chat/completions` to that value and sends both the complete medical prompt and the supplied API credential in an `Authorization: Bearer` header. The implementation does not enforce HTTPS, validate the destination hostname or port, restrict requests to approved model providers, or prevent redirects to another origin. Consequently, command-line input controls the destination to which secrets and sensitive medical information are transmitted. This is particularly significant because the documented input contains patient medical records, while `--appkey` is an authentication secret. The flaw does not independently provide local code execution or elevated operating-system privileges, but it permits disclosure of both categories of sensitive data. ### Attack Path 1. An attacker influences the command invocation, a wrapper co ...[truncated 1300 chars]- Remediation
View remediation
