T09 · Insecure Skill Coding Practices
- Location
scripts/run_generic_fto_report.py:32- Finding
Unrestricted API Endpoint Override Can Exfiltrate Credentials and Confidential FTO Data
- Content
View full analysis
tuple[str, str]: cfg = load_json(API_CONFIG_PATH) return cfg.get("zhihuiya_base_url", "https://connect.zhihuiya.com"), cfg["zhihuiya_api_key"] def api_get(path: str, params: dict, *, timeout: int = 45) -> dict: base, apikey = load_api_config() resp = requests.get(base.rstrip("/") + path, params={"apikey": apikey, **params}, timeout=timeout) resp.raise_for_status() return resp.json() def api_post(path: str, payload: dict, *, timeout: int = 60) -> dict | str: base, apikey = load_api_config() resp = requests.post(base.rstrip("/") + path, params={"apikey": apikey}, json=payload, timeout=timeout) resp.raise_for_status() try: return resp.json() except Exception: return resp.text ``` The configuration path is controllable through a command-line argument: ```python parser.add_argument("--api-config", default=str(DEFAULT_API_CONFIG_PATH), help="skill internal Zhihuiya API configuration JSON") ... API_CONFIG_PATH = pathlib.Path(args.api_config) ``` The reusable client has the same underlying issue at `scripts/zhihuiya_api.py:73-92, 137-164`: ```python def __init__( self, client_id: str = "", client_secret: str = "", api_key: str = "", base_url: str = BASE_URL, timeout: int = 60, ): self.client_id = client_id self.client_secret = client_secret self.api_key = api_key or client_id self.base_url = base_url.rstrip("/") self.timeout = timeout ``` ```python def _post(self, path: str, payload: dict) -> dict: url = f"{self.base_url}{path}" params = {"apikey": self.api_key} resp = requests.post( url, headers=self._he ...[truncated 2644 chars]- Remediation
View remediation
