Tainted flow: 'MAXXIT_API_URL' from os.environ.get (line 18, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
log(f"Starting Volatility Breakout Bot | Market: {MARKET} | Venue: {VENUE}") # 1. Get Club Details club = requests.get(f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/user-details", headers=session.headers).json() user_address = club.get("user_wallet") agent_address = club.get("ostium_agent_address")- Confidence
- 89% confidence
- Finding
- club = requests.get(f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/user-details", headers=session.headers).json()
