T09 · Insecure Skill Coding Practices
- Location
SKILL.md:39- Finding
Bearer Token Disclosure Through an Unrestricted API Base URL Override
- Content
View full analysis
``` ## API Base URL `https://swarmrecall-api.onrender.com` (override with `SWARMRECALL_API_URL` if set) ``` ### Technical Analysis The skill directs the agent to attach `SWARMRECALL_API_KEY` as a bearer token to all API requests while allowing the destination origin to be replaced through `SWARMRECALL_API_URL`. No hostname allowlist, origin validation, or restriction to the official SwarmRecall service is specified. Environment variables can be influenced by parent processes, deployment configuration, compromised automation, or another component operating in the same execution environment. If an attacker controls `SWARMRECALL_API_URL`, authenticated requests can be redirected to an attacker-controlled HTTPS server. The server would receive the bearer token in the `Authorization` header together with any skill registry or task-context data included in the request. TLS does not prevent this attack because the attacker can operate a valid HTTPS endpoint for a domain they control. ### Attack Path 1. The attacker gains control over the agent's deployment configuration or otherwise sets `SWARMRECALL_API_URL` to an attacker-controlled HTTPS origin. 2. The user or agent invokes any SwarmRecall operation, such as listing skills or requesting contextual suggestions. 3. Following the skill instructions, the agent sends the request to the overridden origin. 4. The request includes `Authorization: Bearer `. 5. The attacker records the bearer token and any transmitted request data. 6. The attacker reuses the token against the legitimate SwarmRecall API, subject to the permissions associated with that credential. ### Impact Assessment Successful exploitatio ...[truncated 476 chars]- Remediation
View remediation
