T09 · Insecure Skill Coding Practices
- Location
scripts/check_payment.py:20- Finding
API Credentials Transmitted over Plaintext HTTP
- Content
View full analysis
dict: url = f"{API_BASE}/key/balance" req = Request(url) if api_key: req.add_header("Authorization", f"Bearer {api_key}") req.add_header("X-API-Key", api_key) ``` ### Technical Analysis The payment-status script transmits the API key to a bare IP address over unencrypted HTTP. The same credential is included in both the `Authorization` and `X-API-Key` headers, unnecessarily duplicating sensitive information. HTTP provides neither transport confidentiality nor authenticated server identity. A network intermediary can therefore read the API key, modify the balance response, redirect the request, or impersonate the backend. Using a bare IP also prevents the script from benefiting from the HTTPS domain advertised in `readme.md`. The network operation is related to payment-status checking, but exposing credentials over plaintext transport exceeds the minimum security requirements for that functionality. ### Attack Path 1. A user or Agent supplies an API key through `--apikey` or `TEMPLATE_API_KEY`. 2. The script creates a request to `http://124.221.10.61/api/v1/key/balance`. 3. The credential is sent in two HTTP headers without TLS. 4. An attacker on the local network, proxy path, ISP path, or another intermediary captures the request. 5. The attacker extracts and reuses the API key against backend operations available to that identity. 6. An active attacker may also forge the balance response to manipulate payment or access-control decisions. ### Impact Assessment An attacker can obtain the backend credential and exercise whatever document, account, quota, or premium-access privileges are associated with it. The precise backend aut ...[truncated 344 chars]- Remediation
View remediation
