T09 · Insecure Skill Coding Practices
- Location
scripts/genius_client.py:35- Finding
Unrestricted destination and disabled TLS verification can disclose the corporate SSO session
- Content
View full analysis
ApiResponse: if not path.startswith("/"): path = "/" + path url = self.base_url + path if query: url += "?" + urllib.parse.urlencode(query, doseq=True) headers = { "Cookie": self.cookie, "Accept": "application/json, text/plain, */*", "User-Agent": "genius-client/1.0", } data: Optional[bytes] = None if body is not None: data = json.dumps(body, ensure_ascii=False).encode("utf-8") headers["Content-Type"] = "application/json" req = urllib.request.Request(url=url, method=method.upper(), headers=headers, data=data) try: with urllib.request.urlopen(req, timeout=self.timeout, context=self._ssl_ctx) as resp: ``` ```python p.add_argument("--base-url", default="https://genius.corp.kuaishou.com", help="Base URL") p.add_argument("--cookie", required=True, help="Cookie string, e.g. 'accessproxy_session=xxx; other=yyy'") p.add_argument("--year", type=int, default=2026, help="Year parameter") p.add_argument("--payload-file", help="JSON payload file for detail/products") p.add_argument("--products-payload-file", help="JSON p ...[truncated 2453 chars]- Remediation
View remediation
