T09 · Insecure Skill Coding Practices
- Location
scripts/lib/http.ts:36- Finding
API Key Exposure Through Unredacted Error Messages
- Content
View full analysis
controller.abort(), timeoutMs); const response = await fetch(urlWithParams, { method: "GET", signal: controller.signal, headers: { Accept: "application/json", }, }); clearTimeout(timer); if (!response.ok) { if (!isLastAttempt && (response.status >= 500 || response.status === 429)) { await sleep(DEFAULT_BACKOFF_MS * 2 ** attempt); continue; } throw new CliError( `HTTP request failed with status ${response.status} for ${urlWithParams}`, ExitCode.NETWORK, ); } try { return await response.json(); } catch (jsonError) { throw new CliError( `Failed to parse JSON response from ${urlWithParams}: ${toErrorMessage(jsonError)}`, ExitCode.NETWORK, { cause: jsonError }, ); } ``` Emission of the error in `scripts/weather.ts`: ```ts void main().catch((error: unknown) => { if (error instanceof CliError) { if (error.rawResponse !== undefined) { printJson(error.rawResponse) ...[truncated 2267 chars]- Remediation
View remediation
