T09 · Insecure Skill Coding Practices
- Location
scripts/run.py:171- Finding
Configurable LLM Endpoint Can Disclose Medical Records and API Credentials
- Content
View full analysis
str: url = f"{base.rstrip('/')}/chat/completions" headers = {"Authorization": f"Bearer {appkey}"} if appkey else {} payload = { "model": model, "messages": [{"role": "user", "content": prompt}], "temperature": 0, } response = _http_post(url, payload, headers, timeout=timeout) try: return str(response["choices"][0]["message"]["content"]).strip() except (KeyError, IndexError, TypeError) as exc: raise RuntimeError(f"Unexpected LLM response: {response}") from exc ``` ```python parser.add_argument("--base", default=DEFAULT_LLM_BASE, help=f"内部大模型 base URL(默认:{DEFAULT_LLM_BASE})。") parser.add_argument("--model", default=DEFAULT_LLM_MODEL, help=f"模型名称(默认:{DEFAULT_LLM_MODEL})。") parser.add_argument("--timeout", type=int, default=0, help="HTTP 超时秒数;0 表示一直等待(默认:0)。") parser.add_argument("--appkey", required=True, help="必须传入。内部医疗大模型鉴权 key,使用 Bearer 方式认证。") ``` ```python response = run( payload, base=args.base, model=args.model, appkey=args.appkey, timeout=args.timeout, ) ``` ### Technical Analysis The `--base` argument accepts an arbitrary URL without validating its scheme or hostname. `call_llm()` appends `/chat/completions` to that value and sends both of the following to the resulting endpoint: - The complete prompt containing medical record information. - The API key in an `Authorization: Bearer` header. There is no HTTPS-only check, trusted-host allowlist, or validation that the destination is the documented internal medical-model service. A caller who can influence command-line arguments can ...[truncated 1812 chars]- Remediation
View remediation
