T09 · Insecure Skill Coding Practices
- Location
SKILL.md:75- Finding
Credentials and Bearer tokens may be transmitted to an untrusted cleartext endpoint
- Content
View full analysis
``` ```markdown If the user gives a URL containing `?pw=...`, use that value as `accessCode`. ``` ### Technical Analysis Authentication legitimately requires transmitting an access code and using the resulting Bearer token. However, the Skill permits the base URL to be changed without requiring HTTPS, validating the destination host, or limiting remote destinations to an explicit allowlist. Consequently, an attacker-controlled or mistakenly supplied `GARSS_BASE_URL` can receive the access code during login. The same endpoint can then receive the returned Bearer token in later authenticated requests. HTTP is acceptable for a service strictly bound to loopback, but it does not provide transport confidentiality or server authentication for non-loopback destinations. Reading a password from a URL query parameter also increases exposure because URLs commonly enter browser history, logs, proxy records, telemetry, screenshots, and copied messages. The behavior exceeds minimum privilege when the Skill sends reusable authentication material to any us ...[truncated 1228 chars]- Remediation
View remediation
