T09 · Insecure Skill Coding Practices
- Location
scripts/render-deploy-diff.sh:4- Finding
Render API Key Exfiltration Through an Unrestricted API Base URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but it can send a Render API key to an arbitrary API base URL if that environment variable is set.
Install only if you trust the environment where it will run. Before use, ensure RENDER_API_BASE_URL is unset or pinned to Render's real API endpoint, and avoid running it in CI or shells where untrusted code can set environment variables. Treat RENDER_API_KEY as sensitive and prefer a narrowly scoped token if Render supports it.
scripts/render-deploy-diff.sh:4Render API Key Exfiltration Through an Unrestricted API Base URL
scripts/render-deploy-diff.sh:106Sensitive Render API Responses Exposed Through Process Command-Line Arguments
Referenced artifact was not completely inspected
bash scripts/render-deploy-diff.sh
Referenced artifact was not completely inspected
bash scripts/render-deploy-diff.sh
Referenced artifact was not completely inspected
bash scripts/render-deploy-diff.sh
The skill declares shell and file-reading behavior but does not define any explicit tool scope or permissions boundary. That omission can allow an agent runtime to invoke broader capabilities than intended, increasing the chance of unauthorized file access or command execution when the skill is used.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
#!/usr/bin/env bash
set -euo pipefail
API_BASE="${RENDER_API_BASE_URL:-https://api.render.com/v1}"
TOKEN="${RENDER_API_KEY:-}"
SERVICE_ID="${RENDER_SERVICE_ID:-}"
SERVICE_NAME="${RENDER_SERVICE_NAME:-}"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
#!/usr/bin/env bash
set -euo pipefail
API_BASE="${RENDER_API_BASE_URL:-https://api.render.com/v1}"
TOKEN="${RENDER_API_KEY:-}"
SERVICE_ID="${RENDER_SERVICE_ID:-}"
SERVICE_NAME="${RENDER_SERVICE_NAME:-}"
No suspicious patterns detected.