T09 · Insecure Skill Coding Practices
- Location
modules/btc_llm_decider.py:155- Finding
Provider credentials can be transmitted to an arbitrary environment-configured LLM endpoint
- Content
View full analysis
None: self.provider_name = provider_name self.model_name = model_name self.api_key = api_key self.base_url = (base_url or DEFAULT_OPENAI_BASE_URL).rstrip('/') def complete(self, *, system_prompt: str, user_prompt: str) -> str: body = { 'model': _request_model_name(self.provider_name, self.model_name), 'max_tokens': MAX_MODEL_OUTPUT_TOKENS, 'messages': [ { 'role': 'system', 'content': system_prompt, }, { 'role': 'user', 'content': user_prompt, }, ], 'response_format': { 'type': 'json_schema', 'json_schema': { 'name': 'btc_trade_decision', 'schema': STRICT_SCHEMA, 'strict': True, }, }, } for attempt_index, backoff_seconds in enumerate((0, *LLM_429_BACKOFF_SECONDS)): if backoff_seconds: time.sleep(backoff_seconds) try: raw = _post_json( f'{self.base_url}/chat/completions', body=body, headers={ 'Authorization': f'Bearer {self.api_key}', 'Content-Type': 'application/json', }, ) ``` The same request mechanism is used with a Codex OAuth credential: ```python class CodexOAuthProvider: provider_name = 'c ...[truncated 5221 chars]- Remediation
View remediation
