T09 · Insecure Skill Coding Practices
- Location
scripts/providers/gateway_provider.py:77- Finding
Bearer Credentials and Request Data Can Be Sent to an Unrestricted Gateway Destination
- Content
View full analysis
Dict[str, Any]: """Execute one HTTP request and parse its JSON response.""" data = json.dumps(payload).encode("utf-8") headers = { "Content-Type": "application/json; charset=UTF-8", "Authorization": f"Bearer {api_key}", "ServiceName": "insight", } for attempt in range(MAX_RETRIES): try: _debug_request_summary(action, method, url, payload) if method == "GET": req = urllib.request.Request(url, data=data, headers=headers) req.get_method = lambda: "GET" # type: ignore[assignment] else: req = urllib.request.Request( url, data=data, headers=headers, method="POST" ) with urllib.request.urlopen(req, timeout=DEFAULT_TIMEOUT) as resp: body = resp.read() ``` The destination is constructed without validation: ```python def _build_url(api_base: str, action: str) -> str: return f"{api_base.rstrip('/')}/?Action={action}&Version={API_VERSION}" ``` ### Technical Analysis The gateway provider sends an API key in an `Authorization: Bearer` header together with market-insight request parameters. Authentication data must be transmitted for the gateway functionality, but the destination comes from `ARK_SKILL_API_BASE` or the persisted authentication file and is not constrained to an official service. The implementation does not: - Require HTTPS. - Restrict the hostname to an approved gateway domain. - Reject URL user information or unexpected ports. - Prevent redirects to a different origin. - Require confi ...[truncated 1457 chars]- Remediation
View remediation
