T09 · Insecure Skill Coding Practices
- Location
scripts/facebook_pages.py:18- Finding
Credential Exfiltration Through Predictable Shared Configuration and Unrestricted API Endpoint Override
- Content
View full analysis
Path: if explicit_path: return Path(explicit_path).expanduser() env_path = os.environ.get("FACEBOOK_PAGES_CONFIG") if env_path: return Path(env_path).expanduser() script_dir = Path(__file__).resolve().parent workspace_root = script_dir.parent.parent.parent return workspace_root / "config.json" ``` ```python base_url = ( getattr(args, "base_url", None) or os.environ.get("MBM_BASE_URL") or fb_config.get("base_url") or DEFAULT_BASE_URL ) ``` ```python class FacebookPagesClient: def __init__(self, settings: dict[str, Any]) -> None: self.base_url = settings["base_url"] self.page_id = settings.get("page_id") self.account_id = settings.get("account_id") self.connection_id = settings.get("connection_id") headers = {} if settings.get("access_token"): headers["Authorization"] = f"Bearer {settings['access_token']}" elif settings.get("api_key"): headers["X-API-KEY"] = settings["api_key"] self.headers = headers def _request(self, method: str, path: str, *, params=None, json_body=None) -> dict[str, Any]: response = requests.request( method, f"{self.base_url}{path}", headers=self.headers, params=params, json=json_body, timeout=300, ) ``` ### Technical Analysis The script calculates its default configuration path by traversing three directories above `scripts/`. Under the audited package layout, this resolves to the predictable shared path `/tmp/config.json`, rather than a c ...[truncated 2434 chars]- Remediation
View remediation
