T09 · Insecure Skill Coding Practices
- Location
SKILL.md:91- Finding
Sensitive employee credentials and bearer tokens transmitted over plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 91-96; repeated at lines 147-153 and 183-194
Vulnerability Type: Plaintext transmission of sensitive information
Risk Level: HighVulnerable Code
bash # Call the auto-token endpoint AUTO_TOKEN_URL="${COMPANY_INFO_API_URL:-http://47.116.49.218:3000/api}/auth/auto-token" response=$(curl -s -X POST "$AUTO_TOKEN_URL" \ -H "Content-Type: application/json" \ -d "{\"employee_id\": \"${EMPLOYEE_ID}\", \"employee_name\": \"${EMPLOYEE_NAME}\"}" \ --max-time 10)The plaintext default is also used during token renewal:
bash AUTO_TOKEN_URL="${COMPANY_INFO_API_URL:-http://47.116.49.218:3000/api}/auth/auto-token" EMPLOYEE_ID=$(jq -r '.employee_id' "$TOKEN_CACHE") EMPLOYEE_NAME=$(jq -r '.employee_name' "$TOKEN_CACHE") response=$(curl -s -X POST "$AUTO_TOKEN_URL" \ -H "Content-Type: application/json" \ -d "{\"employee_id\": \"${EMPLOYEE_ID}\", \"employee_name\": \"${EMPLOYEE_NAME}\"}" \ --max-time 10 > /dev/null 2>&1)The bearer token and company query are similarly sent to a plaintext default endpoint:
bash COMPANY_API_URL="${COMPANY_INFO_API_URL:-http://47.116.49.218:3000/api/company-info}" FORCE_REFRESH=false if 用户输入包含 ["重新搜索","更新","刷新","re-search","update","refresh"]; then FORCE_REFRESH=true fi if [ "$FORCE_REFRESH" = true ]; then echo "🔄 强制刷新模式,跳过公司端缓存..." fi response=$(curl -s -X POST "${COMPANY_API_URL}/collect" \ -H "Authorization: Bearer ${API_TOKEN}" \ -H "Content-Type: application/json" \ -d "{\"company_name\": \"${company_name}\", \"force_refresh\": ${FORCE_REFRESH}}" \ --max-time 120) status=$(echo "$response" | jq -r '.status')Technical Analysis
The default API base URL uses unencrypted HTTP and a bare IP address. Unless every deployment explicitly overrides
COMPANY_INFO_API_URLwith a secure HTTPS endpoint, the Skill transmits the follow ...[truncated 2310 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the plaintext HTTP fallback and require an HTTPS URL:
bash : "${COMPANY_INFO_API_URL:?COMPANY_INFO_API_URL must be configured with an HTTPS endpoint}" case "$COMPANY_INFO_API_URL" in https://*) ;; *) echo "Refusing non-HTTPS API endpoint" >&2; exit 1 ;; esac - Use an organization-controlled DNS hostname with a certificate issued for that hostname rather than a bare IP address.
- Retain curl certificate verification and do not introduce
-kor--insecure. - Consider certificate or public-key pinning where the operational certificate-rotation process can support it safely.
- Rotate any tokens that may previously have crossed the plaintext endpoint.
- Restrict bearer tokens by role, endpoint, employee, and expiration time. Use short-lived access tokens where possible.
- Add server-side replay protections, access auditing, rate limits, and anomaly detection.
- Avoid placing sensitive identity or authentication material in URLs, logs, or diagnostic output.
- Fail closed when the endpoint is missing or insecure rather than silently falling back to HTTP.
- Remove the plaintext HTTP fallback and require an HTTPS URL:
