T09 · Insecure Skill Coding Practices
- Location
lead-enrich.sh:4- Finding
API Credential Disclosure Through Unrestricted Endpoint Overrides
- Content
View full analysis
"$err")"; then ``` ### Technical Analysis The script permits `PRISMFY_API_URL`, `PRISMFY_API_ROOT`, and `PRISMFY_ME_URL` to control network destinations without validating their schemes, hostnames, ports, or trust boundaries. Both quota and search requests attach `PRISMFY_API_KEY` as a bearer token. Consequently, a manipulated environment can redirect the request to an attacker-controlled endpoint. The script also permits plain HTTP URLs, which can expose the bearer token and request data to network interception. The search payload can contain company names, domains, person names, roles, geographic criteria, and ICP information. Therefore, endpoint redirection can disclose both the API credential and lead-enrichment input data. This is not evidence of intentional exfiltration: the normal default destination is the documented Prismfy API. The vulnerability arises because credential-bearing endpoint overrides are accepted without security validation. ### Attack Path 1. An attacker gains the ability to influence the environment used to launch the Skill, such as through a compromised shell profile, CI configuration, wrap ...[truncated 1599 chars]- Remediation
View remediation
