T09 · Insecure Skill Coding Practices
- Location
polymarket_brain_orchestrator.py:29- Finding
Live Discord Webhook Credentials Committed Across Source, Configuration, Documentation, and Tests
- Content
View full analysis
" PHASE4_DISCORD_WEBHOOK = "https://discord.com/api/webhooks/1483478506070474922/" ``` The same analysis webhook is also used as an executable default: ```python webhook_url = sys.argv[1] if len(sys.argv) > 1 else "https://discord.com/api/webhooks/1483478506070474922/" ``` The tokens are redacted in this report to avoid further disclosure. Complete, apparently live values are present in the identified project files. ### Technical Analysis A Discord webhook URL contains both an identifier and a secret token. Possession of the complete URL authorizes message submission without a separate login, making it a bearer credential. The project embeds two complete webhook credentials directly in executable scripts and duplicates one of them in configuration files, documentation, snapshots, and network-executing tests. This contradicts the project's own security guidance in `SKILL.md:356-361`, which states that webhook URLs should not be committed and should instead be obtained from environment variables. Several test scripts perform real network requests against these credentials rather than using an HTTP mock. Consequently, simply running a test can modify a production Discord channel. Duplication across many files also makes reliable rotation and removal difficult. ...[truncated 1475 chars]- Remediation
View remediation
