T09 · Insecure Skill Coding Practices
- Location
scripts/run.py:69- Finding
Unrestricted API Endpoint Can Expose Credentials and Sensitive Medical Data
- Content
View full analysis
str: payload = { "model": model, "temperature": temperature, "messages": [ {"role": "system", "content": system_prompt}, {"role": "user", "content": user_prompt}, ], } try: req = Request( api_url, data=json.dumps(payload, ensure_ascii=False).encode("utf-8"), headers={ "Content-Type": "application/json", "Authorization": f"Bearer {appkey}", }, ) resp = urlopen(req, timeout=timeout) ``` The destination is exposed as an unrestricted command-line argument: ```python p.add_argument("--api-url", default=DEFAULT_API_URL, help="OpenAI compatible API endpoint") ``` The user-controlled value is passed directly to the request function: ```python out["answer"] = call_llm( api_url=args.api_url, model=args.model, appkey=args.appkey, system_prompt=args.system_prompt, user_prompt=user_prompt, temperature=float(args.temperature), timeout=int(args.timeout), ) ``` ### Technical Analysis The `--api-url` option accepts an arbitrary URL without validating its scheme or hostname. `call_llm` then sends an `Authorization: Bearer` header containing the supplied application key and a request body containing the medical question to that destination. Consequently, anyone able to influence the script's invocation or configuration can redirect the request to an attacker-controlled server. The implementation does not require HTTPS and does not rest ...[truncated 1790 chars]- Remediation
View remediation
