T09 · Insecure Skill Coding Practices
- Location
scripts/cli.py:145- Finding
Payment notification data and bearer credentials are transmitted over unencrypted HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/cli.py:145-154; insecure default endpoint documented atSKILL.md:66andREADME.md:29
Vulnerability Type: Cleartext transmission of sensitive information
Risk Level: HighVulnerable Code
python def api_get(cfg, path, params=None): url = cfg["server_url"] + path if params: url += "?" + urllib.parse.urlencode({k: v for k, v in params.items() if v}) return http_request("GET", url, headers={"Authorization": f"Bearer {cfg['api_key']}"}) def api_post(cfg, path, body=None): url = cfg["server_url"] + path return http_request("POST", url, headers={"Authorization": f"Bearer {cfg['api_key']}"}, body=body)The Skill directs users to the following default endpoint:
bash python3 "$SKILL_DIR/scripts/cli.py" register --server http://8.136.213.223:9010 --name <developer-name>Technical Analysis
The API client attaches the relay API key as a bearer credential to requests constructed directly from
server_url. The implementation does not require HTTPS or reject cleartext HTTP endpoints. The documented default ishttp://8.136.213.223:9010, causing the bearer credential to be transmitted without transport encryption.The same cleartext server is used for registration, notification retrieval, SSE streaming, and acknowledgement requests. The generated Alipay callback URL also uses HTTP. Consequently, sensitive callback contents can cross the network in plaintext, including order numbers, Alipay transaction numbers, payment amounts, application IDs, notification identifiers, signatures, and the complete raw callback body.
Although sending notification data to a relay is necessary for the declared functionality, sending it over unencrypted HTTP is not necessary and violates least-exposure principles.
Attack Path
- A victim follows the documented registration command and connects to the HTTP relay. 2 ...[truncated 1244 chars]
- Remediation
View remediation
Remediation Suggestions
- Require
https://for registration, API access, SSE streaming, and generated callback URLs. - Reject HTTP server URLs before sending registration details or credentials.
- If local development requires HTTP, permit it only for loopback addresses through an explicit opt-in flag with a prominent warning.
- Replace the bare IP default with a trusted DNS hostname backed by a valid TLS certificate.
- Continue using Python's default certificate and hostname verification, and do not add certificate-bypass options.
- Rotate existing API keys and notification tokens because credentials previously sent over HTTP should be considered potentially exposed.
- Document the categories of payment data processed by the relay and obtain explicit user confirmation before directing callbacks through a third-party service.
- Consider short-lived credentials and a server-side credential revocation mechanism to reduce the impact of interception.
- Require
