T09 · Insecure Skill Coding Practices
- Location
lib/config.py:544- Finding
API credentials can be redirected to an arbitrary endpoint
- Content
View full analysis
dict[str, str]: headers = {"Accept": "application/json"} if self._config.api_key: headers["X-API-Key"] = self._config.api_key.get_secret_value() if authenticated: if self._jwt_provider is None: raise PredictApiError( "Authenticated predict.fun request requires a JWT provider.", method="AUTH", ) headers["Authorization"] = f"Bearer {await self._jwt_provider()}" return headers ``` ### Technical Analysis `PREDICT_API_BASE_URL` is accepted directly from the environment without validating its scheme or hostname. The resulting value becomes the base URL for the HTTP client. The client adds `PREDICT_API_KEY` to every request when configured. Authenticated requests also receive a bearer JWT. Consequently, a malicious or accidentally modified environment file can redirect credential-bearing requests to an arbitrary endpoint. HTTPS alone would not fully resolve the issue because an attacker can operate a valid HTTPS domain. Production credentials should only be attached when the destination matches an explicitly trusted service identity. ### Attack Path 1. An attacker modifies the Skill's `.env`, controls `PREDICTCLAW_ENV_FILE`, influences the process environment, or convinces the user to add a custom endpoint. 2. The attacker sets: ```dotenv PREDICT_API_BASE_ ...[truncated 984 chars]- Remediation
View remediation
