T09 · Insecure Skill Coding Practices
- Location
scripts/buy.sh:61- Finding
Remote API Responses Are Embedded into Executable Python Source
- Content
View full analysis
/dev/null || echo "$RESPONSE" ``` From `scripts/sell.sh:61-71`: ```bash python3 << EOF import json data = json.loads('''$RESPONSE''')['data'] print(f"Token: {data['artist_name']}") print(f"Amount: {data['amount']} token") print(f"Refund: \${data['net_refund_usdc']:.2f} USDC") print(f"Fee: \${data.get('fee_usdc', 0):.2f} USDC") print(f"Tx Hash: {data.get('tx_hash', 'pending')}") EOF ``` From `scripts/sell.sh:77`: ```bash python3 -c "import json; d=json.loads('''$RESPONSE'''); print(d.get('error', d))" 2>/dev/null || echo "$RESPONSE" ``` ### Technical Analysis The scripts interpolate an HTTP response directly into Python source code inside a triple-quoted string. Although `json.loads()` is intended to parse the response as data, interpolation happens before Python parses the resulting program. A response containing a sequence that closes the triple-quoted string can introduce additional Python statements. Therefore, a maliciou ...[truncated 1840 chars]- Remediation
View remediation
