T09 · Insecure Skill Coding Practices
- Location
scripts/hik_open_video_recording.py:125- Finding
Credentials and bearer tokens can be transmitted to an arbitrary destination
- Content
View full analysis
str: normalized = base_url.strip() if not normalized: raise ApiError("base URL must not be empty") return normalized.rstrip("/") def resolve_base_url(explicit_base_url: str | None) -> str: if explicit_base_url: return normalize_base_url(explicit_base_url) env_base_url = os.getenv(BASE_URL_ENV_VAR) if env_base_url: return normalize_base_url(env_base_url) return DEFAULT_BASE_URL ``` ```python def fetch_access_token( base_url: str, client_id: str, client_secret: str, timeout: float, ) -> dict[str, Any]: status, payload = http_json_request( method="POST", url=base_url.rstrip("/") + TOKEN_PATH, headers=None, timeout=timeout, form_body={ "client_id": client_id, "client_secret": client_secret, "grant_type": "client_credentials", "scope": "app", }, ) ``` ```python token, refreshed = resolve_access_token(base_url, timeout, cache_file, explicit_token) headers = {"Authorization": f"Bearer {token}"} status, payload = http_json_request( method=spec.method, url=spec.build_url(base_url), headers=headers, timeout=timeout, json_body=spec.json_body, ) ``` ```python parser.add_argument("--base-url", default=None) parser.add_argument("--access-token", default=None) parser.add_argument("--timeout", type=float, default=DEFAULT_TIMEOUT) parser.add_argument("--token-cache-file", default=str(DEFAULT_TOKEN_CACHE)) parser.add_argument("--format", choices=("text", "json"), default="text") ``` ### Technical Analysis The Skill must transmit crede ...[truncated 3252 chars]- Remediation
View remediation
