T09 · Insecure Skill Coding Practices
- Location
scripts/utils/request.js:14- Finding
Unbounded HTTP Response Buffering Enables Memory Exhaustion
- Content
View full analysis
(body += chunk)); ``` ### Technical Analysis The shared HTTP client accumulates every response chunk in an in-memory string without enforcing a maximum response size. JSON parsing occurs only after the complete response has been received. All search, post, and comment API operations use this request function. A compromised, malicious, malfunctioning, or unexpectedly verbose API endpoint could therefore return an excessively large response and cause uncontrolled memory consumption. The configured request timeout limits request duration but does not reliably limit the total response size received within that interval. Because response parsing and certain response failures are retryable, repeated attempts may reproduce the resource exhaustion unless oversized-response errors are explicitly marked as non-retryable. ### Attack Path 1. A user or Agent invokes a search, post, or comment command. 2. The Skill sends an HTTPS request containing the relevant parameters to the fixed API host, `www.guaikei.com`. 3. The API endpoint, or infrastructure serving it, returns an excessively large response body or continuously sends data within the timeout window. 4. The `data` handler repeatedly appends incoming chunks to `body`. 5. Process memory usage grows without an application-level bound. 6. The Node.js process experiences severe memory pressure or terminates with an out-of-memory error. 7. If the failure is considered retryable, subsequent attempts may repeat the memory consumption. ### Impact Assessment This vulnerability does not grant additional operating-system privileges, arbitrary code execution, or access to unrelated credentials. Its primary impact is availability: - Termination of ...[truncated 524 chars]- Remediation
View remediation
{ receivedBytes += Buffer.byteLength(chunk, "utf8"); if (receivedBytes > MAX_RESPONSE_BYTES) { const err = new Error("API response exceeds the permitted size"); err.code = "ERR_RESPONSE_TOO_LARGE"; err.nonRetryable = true; req.destroy(err); return; } body += chunk; }); ``` ]]>
