T09 · Insecure Skill Coding Practices
- Location
templates/config.json:2- Finding
API Credential and Search Queries Are Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
templates/config.json:2-3, with request behavior defined inreferences/zenlin_search_api.md:66-76
Vulnerability Type: Plaintext transmission of credentials and user data
Risk Level: HighVulnerable Code
templates/config.json:1-5:json { "Zeelin_Website_Url": "http://search-skill.zeelin.cn", "Zeelin_Api_Url": "http://search-skill.zeelin.cn:5000/api/es/search/natural", "Zeelin_Api_Key": "" }references/zenlin_search_api.md:66-76defines the following request structure:http POST ${Zeelin_Api_Url} Content-Type: application/json; charset=utf-8 app-key: ${Zeelin_Api_Key} sign: ${sign} timestamp: ${timestamp} { "question_name": "Natural-language search query" }Technical Analysis
The default API URL uses unencrypted HTTP. At the same time, every request includes the raw
Zeelin_Api_Keyin theapp-keyheader and the user's natural-language query in the request body.The HMAC-SHA256 signature only authenticates a value derived from the key and timestamp. It does not encrypt the HTTP headers or body. Consequently, any party capable of observing traffic between the agent and the configured service can read the API key, timestamp, signature, and search query.
The Skill instructions further state that
Zeelin_Api_Urlmust not be checked or questioned. This means the Skill does not enforce HTTPS, validate the destination hostname, or prevent credentials from being sent to an insecure or modified endpoint.Attack Path
- A user places a valid Zeelin API key in
templates/config.json. - The user invokes the Skill with a search query.
- The Skill reads the key and constructs authentication headers containing the raw key.
- The Skill sends the headers and query to the default
http://search-skill.zeelin.cn:5000endpoint. - An attacker with access to the local network, proxy infrastructure, router, D ...[truncated 1262 chars]
- A user places a valid Zeelin API key in
- Remediation
View remediation
Remediation Suggestions
- Replace both default HTTP URLs with HTTPS URLs backed by valid TLS certificates.
- Reject any
Zeelin_Api_Urlwhose scheme is nothttps. - Validate the API hostname against an explicit allowlist before attaching authentication headers.
- Resolve redirects carefully and refuse redirects to HTTP or unapproved hosts.
- Do not print or log
app-key,sign, or other authentication values when printing request parameters. - Store the API key in a protected secret store or environment variable rather than a general JSON configuration file where the runtime supports secure secret management.
- Apply restrictive filesystem permissions to any local configuration containing the key.
- Add short request timeouts and certificate validation without disabling TLS verification.
- Rotate any API keys that may previously have been sent through the plaintext endpoint.
- Remove the instruction that forbids validation of
Zeelin_Api_Url; configuration validation must occur before credentials are transmitted.
