T09 · Insecure Skill Coding Practices
- Location
scripts/bitcoin_client.py:91- Finding
CoinGecko API Key Exposed in URL Query String
- Content
View full analysis
- Remediation
View remediation
Optional[Any]: request_headers = { "Accept": "application/json", "User-Agent": "HermesAgent/1.0", } if headers: request_headers.update(headers) req = urllib.request.Request(url, headers=request_headers) # Existing request and retry handling follows. def _get_price_usd(currency: str = "USD") -> Optional[float]: currency_lower = currency.lower() cg_key = os.getenv("COINGECKO_API_KEY", "") url = ( "https://api.coingecko.com/api/v3/simple/price" f"?ids=bitcoin&vs_currencies={currency_lower}" ) auth_headers = {"x-cg-pro-api-key": cg_key} if cg_key else {} data = _http_get_json(url, timeout=10, retries=1, headers=auth_headers) ``` ]]>
