T09 · Insecure Skill Coding Practices
- Location
scripts/mcd_rpc.py:14- Finding
Bearer Token Exfiltration Through an Unrestricted CLI Endpoint
- Content
View full analysis
- Remediation
View remediation
str: parsed = urlparse(value) if ( parsed.scheme != "https" or parsed.hostname != "mcp.mcd.cn" or parsed.port not in (None, 443) or parsed.username is not None or parsed.password is not None ): raise ValueError("MCP credentials may only be sent to https://mcp.mcd.cn") return value URL = validate_url(os.getenv("MCD_MCP_URL", OFFICIAL_URL)) ``` ]]>
