T09 · Insecure Skill Coding Practices
- Location
scripts/tavily.py:27- Finding
Bearer Credential May Be Disclosed Before Redirect Validation
- Content
View full analysis
Dict[str, str]: # Only read the single intended credential from the environment. api_key = _environ.get("TAVILY_API_KEY") if not api_key: _die("TAVILY_API_KEY environment variable not set") return { "Authorization": f"Bearer {api_key}", "Accept": "application/json", "User-Agent": "hermes-skill-tavily/1.0", } def _try_parse_json(raw: bytes) -> Dict[str, Any]: text = raw.decode("utf-8", errors="replace") try: parsed = json.loads(text) except Exception: return {"raw": text} if isinstance(parsed, dict): return parsed return {"value": parsed} def _request(method: str, path: str, *, json_body: Optional[dict] = None, http_timeout: float = 60.0) -> Dict[str, Any]: # Hardcode the API host to prevent exfil via injected base URL overrides. url = f"{TAVILY_API_BASE_URL}{path}" headers = _headers() data = None if json_body is not None: headers = dict(headers) headers["Content-Type"] = "application/json" data = json.dumps(json_body).encode("utf-8") req = urllib.request.Request(url, data=data, headers=headers, method=method) try: with urllib.request.urlopen(req, timeout=http_timeout) as resp: final_url = resp.geturl() if not final_url.startswith(TAVILY_API_BASE_URL + "/"): _die(f"Unexpected redirect: {final_url}", code=1) raw = resp.read() except urllib.error.HTTPError as e: raw = e.read() payload = _try_parse_json(raw) _die(f"HTTP {e.code}: {payload}", code=1) except urllib.error.URLError as e: _die(f"Request failed: {e.reason}", code=1) except Exception as e: _die(f"Request failed: {type ...[truncated 2525 chars]- Remediation
View remediation
