T09 · Insecure Skill Coding Practices
- Location
scripts/prophecy.sh:3- Finding
Environment-Controlled API Endpoint Can Receive Stored Credentials
- Content
View full analysis
/dev/null) ``` ### Technical Analysis The script reads the persistent bearer credential from `~/.config/molt/credentials.json` and sends it to the endpoint specified by `MOLT_API_BASE`. Because this environment variable is accepted without hostname validation, an HTTPS requirement, an allowlist, or user confirmation, any inherited environment value can determine the recipient of the credential. This exceeds the minimum privilege needed for authenticated prophecy submission. Endpoint overrides may be useful for testing, but production credentials should never automatically accompany requests to arbitrary test or third-party endpoints. ### Attack Path 1. A malicious wrapper, compromised launcher, shell configuration, or other process sets `MOLT_API_BASE` to an attacker-controlled URL. 2. A registere ...[truncated 853 chars]- Remediation
View remediation
