Tainted flow: 'API' from os.getenv (line 13, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
agent_id = load_cert() print(f"📜 Agent ID: {agent_id}\n") status = requests.get(f"{API}/trust-handshake/status/{args.handshake_id}").json() if status["status"] == "completed": print(f"✅ Already done! Session Key: {status['session_key']}") return- Confidence
- 90% confidence
- Finding
- status = requests.get(f"{API}/trust-handshake/status/{args.handshake_id}").json()
