T09 · Insecure Skill Coding Practices
- Location
contact-find.sh:4- Finding
Bearer API Credential Can Be Transmitted to an Untrusted Configurable Endpoint
- Content
View full analysis
"$err")"; then ``` ### Technical Analysis The script takes request destinations from the `PRISMFY_API_URL`, `PRISMFY_API_ROOT`, and `PRISMFY_ME_URL` environment variables. It does not validate their URL schemes, hostnames, ports, or trust relationships before attaching the `PRISMFY_API_KEY` as a bearer credential. Consequently, any party able to influence the process environment or the wrapper used to invoke this script can redirect authenticated requests to an arbitrary destination. The risk is especially significant because the authorization header is added unconditionally after only checking that the API key is present. The search request also includes person, company, domain, role, and geographic query data in its JSON payload. The default endpoint is the expected Prismfy HTTPS service, so exploitation requires influence over configuration or the invocation environment. This is nevertheless ...[truncated 1495 chars]- Remediation
View remediation
