{"record":{"id":"6c3f5a2d730819fa","repo":"affaan-m/ECC","slug":"remote-instinct-imports-require-https-urls","errorCode":null,"errorMessage":"remote instinct imports require https URLs","messagePattern":"remote instinct imports require https URLs","errorType":"validation","errorClass":"ValueError","httpStatus":null,"severity":"error","filePath":"skills/continuous-learning-v2/scripts/instinct-cli.py","lineNumber":193,"sourceCode":"\ndef _validate_instinct_id(instinct_id: str) -> bool:\n    \"\"\"Validate instinct IDs before using them in filenames.\"\"\"\n    if not instinct_id or len(instinct_id) > 128:\n        return False\n    if \"/\" in instinct_id or \"\\\\\" in instinct_id:\n        return False\n    if \"..\" in instinct_id:\n        return False\n    if instinct_id.startswith(\".\"):\n        return False\n    return bool(re.match(r\"^[A-Za-z0-9][A-Za-z0-9._-]*$\", instinct_id))\n\n\ndef _validate_import_url(source: str) -> str:\n    \"\"\"Validate remote instinct imports before opening a network connection.\"\"\"\n    parsed = urllib.parse.urlparse(source)\n    if parsed.scheme != \"https\":\n        raise ValueError(\"remote instinct imports require https URLs\")\n    if not parsed.hostname:\n        raise ValueError(\"remote import URL is missing a hostname\")\n\n    try:\n        addr_infos = socket.getaddrinfo(parsed.hostname, parsed.port or 443, type=socket.SOCK_STREAM)\n    except socket.gaierror as exc:\n        raise ValueError(f\"remote import host could not be resolved: {parsed.hostname}\") from exc\n\n    for family, _, _, _, sockaddr in addr_infos:\n        host = sockaddr[0]\n        try:\n            ip = ipaddress.ip_address(host)\n        except ValueError:\n            continue\n        if (\n            ip.is_private\n            or ip.is_loopback\n            or ip.is_link_local","sourceCodeStart":175,"sourceCodeEnd":211,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/continuous-learning-v2/scripts/instinct-cli.py#L175-L211","documentation":"Raised by _validate_import_url when a remote instinct import URL does not use the https scheme. Because the CLI will fetch and parse the remote content, it refuses plaintext http to prevent tampered or downgraded downloads. Only https:// URLs pass this first validation gate.","triggerScenarios":"Calling the import command with a source like http://example.com/instincts.yaml, ftp://..., or a bare host with no scheme so urlparse yields scheme ''.","commonSituations":"Copying an http link from an old README or internal server; a URL built from a config variable that defaults to http; pasting a URL without its scheme.","solutions":["Change the URL to use https:// and retry.","If the host does not support https, download the file over a trusted channel and import it from a local path instead.","Verify the scheme programmatically before calling: urllib.parse.urlparse(source).scheme == 'https'.","Fix upstream links/config that emit http URLs."],"exampleFix":"# before\nurl = \"http://example.com/instincts.yaml\"\n# after\nurl = \"https://example.com/instincts.yaml\"","handlingStrategy":"validation","validationCode":"from urllib.parse import urlparse\nif urlparse(source).scheme != \"https\":\n    raise ValueError(\"import source must be an https URL\")","typeGuard":null,"tryCatchPattern":"try:\n    cli_import(url=source)\nexcept ValueError as e:\n    if \"https\" in str(e):\n        print(\"upgrade the URL to https://\")","preventionTips":["Store https URLs in configs and docs","Never paste http:// links into import commands","Normalize bare hosts by prepending https://","Prefer fetching raw file URLs over redirecting pages"],"tags":["python","security","url-validation","network"],"backgroundTag":"invalid-url","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}