T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:82- Finding
API Credential Exposed in URL Query Strings
- Content
View full analysis
``` TLS protects the complete request path while it is in transit, but URL query strings are frequently recorded by destination servers, reverse proxies, web application firewalls, observability systems, access logs, debugging tools, and error-reporting platforms. Consequently, the credential can be exposed to more systems and operators than necessary. The query APIs can retry up to 20 times, which may cause the credential-bearing URL to be processed and recorded repeatedly. The token is not printed in normal CLI output, but placing it in the URL remains an insecure credential transport mechanism. ### Attack Path 1. A user config ...[truncated 1190 chars]- Remediation
View remediation
