T09 · Insecure Skill Coding Practices
- Location
SKILL.md:105- Finding
Generated Articles Are Published to a Hard-Coded Endpoint over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 105–110
Vulnerability Type: Plaintext transmission to a hard-coded external publication endpoint
Risk Level: Mediumbash # 保存到 workspace cp /tmp/article.md /root/articles/$(date +%Y-%m-%d)/tech-insight-daily.md # 发布到公众号 curl -X POST http://118.25.114.18:3001/api/articles \ -H "Content-Type: application/json" \ -d '{"title": "...", "content": "...", "category": "AI技术"}'Technical Analysis
The skill instructs the agent to submit generated article content and associated metadata to the hard-coded external IP address
118.25.114.18over unencrypted HTTP. HTTP provides neither transport confidentiality nor server authentication. An attacker able to observe or interfere with the network path could read the submitted content, alter the request, or impersonate the publication service through techniques such as network redirection.The command also provides no application-level authentication, request signing, integrity verification, or explicit user-confirmation control. Although the README describes remote publication as optional, the standard save-and-publish procedure in
SKILL.mdpresents the request directly. The hard-coded raw IP further prevents normal domain-based ownership validation and makes safe environment-specific configuration difficult.This finding is limited to exposure and manipulation of the publication request. The reviewed files do not establish that the endpoint returns executable content or that the skill executes a remote payload.
Attack Path
- A user invokes the skill to collect sources and generate an article.
- The workflow creates
/tmp/article.mdand copies it into/root/articles. - The agent follows the documented publication procedure and sends the article title, content, and category to
http://118.25.114.18:3001/api/articles. - An attacker positioned on the network path intercepts or redirects the plaintext HTTP connection.
- The ...[truncated 880 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the plaintext URL with a verified HTTPS endpoint using a valid certificate and mandatory certificate validation.
- Use a trusted domain rather than a raw IP address, and document how operators can verify ownership of the publication service.
- Move the endpoint into environment-specific trusted configuration instead of hard-coding it in skill instructions.
- Require authentication, such as a narrowly scoped API token obtained from a secret manager. Do not embed credentials in the skill package or command history.
- Add request-integrity controls, such as authenticated API requests or signed payloads, where supported by the service.
- Make remote publication explicitly opt-in. Before transmission, show the destination and the categories of data being sent and require user confirmation.
- Default to local-only article storage when remote publication has not been expressly requested.
- Avoid predictable shared temporary paths where practical. Create temporary files with restrictive permissions and unique names, then delete them securely after use.
- Add failure handling so TLS, authentication, or destination-verification errors stop publication rather than falling back to an insecure connection.
