T09 · Insecure Skill Coding Practices
- Location
config.json:2- Finding
API Credentials and User Content Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
config.json:2,SKILL.md:4,38,43,paper_client.py:31-36,52-59,91-97,135-153
Vulnerability Type: Sensitive information transmitted over an unencrypted network connection
Risk Level: HighVulnerable Code
config.json:1-5:json { "apiBaseUrl": "http://weakaccept.top:8000/", "apiKey": "", "defaultAuthorName": "" }paper_client.py:31-36:python def get_headers(config): """Get request headers (including API Key if configured)""" headers = {} if config.get("apiKey"): headers["X-API-Key"] = config["apiKey"] return headerspaper_client.py:52-59:python def cmd_list(args): """Fetch paper list""" config = load_config() url = f"{get_api_base(config)}/v1/papers" params = {"limit": args.limit}python headers = get_headers(config) response = requests.get(url, params=params, headers=headers)paper_client.py:135-153:python def cmd_comment(args): """Add comment""" config = load_config() url = f"{get_api_base(config)}/public/papers/{args.paper_key}/comments" # If author name not specified, use default from config author_name = args.author_name or config.get("defaultAuthorName", "Anonymous") data = { "content": args.content, "author_name": author_name } response = requests.post( url, headers={"Content-Type": "application/json"}, json=data )Technical Analysis
The default API URL uses plaintext HTTP rather than HTTPS. The client derives every endpoint from this value without validating the scheme or requiring transport encryption.
When an API key is configured,
get_headers()places it in theX-API-Keyrequest header for the authenticated list and paper-detail operations. Review submissions separately transmit user-provide ...[truncated 2161 chars]- Remediation
View remediation
Remediation Suggestions
- Replace the default endpoint with an HTTPS URL backed by a valid certificate:
json { "apiBaseUrl": "https://weakaccept.top/", "apiKey": "", "defaultAuthorName": "" } - Validate
apiBaseUrlbefore making any request and reject schemes other thanhttps. - At minimum, unconditionally reject HTTP whenever an API key, author identity, comment, or other potentially sensitive value would be transmitted.
- Keep normal TLS certificate and hostname verification enabled. Do not introduce
verify=False. - Consider restricting the permitted host to the expected API hostname to reduce accidental credential transmission to an attacker-controlled endpoint.
- Store API keys outside the project file where possible, such as in a protected environment variable or operating-system credential store.
- Rotate any API key that has already been used through the plaintext endpoint.
- Add connection and read timeouts and handle
requestsexceptions so a malicious or unavailable endpoint cannot hang the client indefinitely.
- Replace the default endpoint with an HTTPS URL backed by a valid certificate:
