Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)
- Category
- Data Flow
- Confidence
- 96% confidence
- Finding
The request destination is influenced by the user-configurable host value, which can come from the A7W_HOST environment variable or stored config, and the client always attaches the Bearer API key before sending the request. This enables credential exfiltration to an attacker-controlled endpoint if the host is overridden, making the tainted network flow a real security issue in the context of an agent skill that may run with user secrets loaded.
- Content
python headers["Content-Type"] = "application/json" req = urllib.request.Request(url, data=data, headers=headers, method=method) try: with urllib.request.urlopen(req, timeout=timeout) as resp: raw = resp.read().decode("utf-8", "replace") status = resp.status except urllib.error.HTTPError as exc:
