T09 · Insecure Skill Coding Practices
- Location
SKILL.md:21- Finding
Configurable API Origin Can Exfiltrate the Bearer API Key
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 21–23, 97–104, 136–143, and 158–171
Vulnerability Type: Unrestricted credential destination
Risk Level: MediumVulnerable Code
yaml - name: REELYZE_BASE_URL required: false description: API base URL. Defaults to https://api.getreelyze.com.The configurable origin is subsequently used in authenticated requests:
bash curl -s -X POST "$REELYZE_BASE_URL/v1/analyze" \ -H "Authorization: Bearer $REELYZE_API_KEY" \ -H "Content-Type: application/json" \ -d '{"url":"https://www.instagram.com/reel/XXXX/"}'The same pattern is used for job polling and content-generation endpoints:
bash curl -s "$REELYZE_BASE_URL/v1/jobs/abc..." \ -H "Authorization: Bearer $REELYZE_API_KEY"bash curl -s -X POST "$REELYZE_BASE_URL/v1/script" \ -H "Authorization: Bearer $REELYZE_API_KEY" -H "Content-Type: application/json" \ -d '{"topic":"how I edit reels in 10 minutes","duration_seconds":30,"language":"English"}'Technical Analysis
The Skill allows
REELYZE_BASE_URLto be supplied through the environment without requiring HTTPS or validating the destination hostname. It then attaches the sensitiveREELYZE_API_KEYas an HTTP bearer credential to requests made to that configurable origin.This creates a credential-confusion vulnerability: the authentication token intended for
api.getreelyze.comis sent to whichever server is named byREELYZE_BASE_URL. The Skill provides no origin allowlist, hostname verification policy, or user confirmation before sending the credential to a non-default destination.The issue is exploitable when an attacker can influence the Agent's environment, deployment configuration, wrapper script, or other mechanism that sets
REELYZE_BASE_URL. It does not require arbitrary code execution inside the Skill.Attack Path
- The victim configures a valid
REELYZE_API_KEYfor the Agent. - An attacker or compromised deployment co ...[truncated 1185 chars]
- The victim configures a valid
- Remediation
View remediation
Remediation Suggestions
-
Pin authenticated requests to the documented production origin:
text https://api.getreelyze.com -
If custom endpoints are operationally necessary, enforce an explicit allowlist of trusted HTTPS origins before attaching the Authorization header.
-
Reject base URLs that:
- Use plaintext HTTP.
- Contain embedded user information.
- Resolve to unapproved hostnames.
- Use unexpected ports.
- contain paths, queries, or fragments where only an origin is expected.
-
Normalize and compare the URL scheme, hostname, and port rather than relying on string-prefix checks.
-
Do not forward the Authorization header if a request is redirected to a different origin.
-
Require explicit user confirmation before sending a credential to any non-default development or staging endpoint.
-
Document that
REELYZE_BASE_URLis security-sensitive and must not be controlled by untrusted users or inherited from untrusted environment configuration. -
Rotate any API key that may previously have been used with an untrusted base URL, and review account usage for unauthorized quota consumption.
-
