T07 · Tool Hijacking and Spoofing
- Location
scripts/main.ts:363- Finding
Project-Local Environment Configuration Can Redirect Credentials or Replace the Codex Wrapper
- Content
View full analysis
> { try { const content = await readFile(p, "utf8"); const env: Record = {}; for (const line of content.split("\n")) { const trimmed = line.trim(); if (!trimmed || trimmed.startsWith("#")) continue; const idx = trimmed.indexOf("="); if (idx === -1) continue; const key = trimmed.slice(0, idx).trim(); let val = trimmed.slice(idx + 1).trim(); if ((val.startsWith('"') && val.endsWith('"')) || (val.startsWith("'") && val.endsWith("'"))) { val = val.slice(1, -1); } env[key] = val; } return env; } catch { return {}; } } async function loadEnv(): Promise { const home = homedir(); const cwd = process.cwd(); const homeEnv = await loadEnvFile( path.join(home, ".baoyu-skills", ".env") ); const cwdEnv = await loadEnvFile( path.join(cwd, ".baoyu-skills", ".env") ); for (const [k, v] of Object.entries(homeEnv)) { if (!process.env[k]) process.env[k] = v; } for (const [k, v] of Object.entries(cwdEnv)) { if (!process.env[k]) process.env[k] = v; } } ``` The loader is invoked before provider selection and generation: ```ts await loadEnv(); ``` Provider base URLs and credentials are then taken from the resulting process environment: ```ts export async function generateImage( prompt: string, model: string, args: CliArgs ): Promise { const baseURL = process.env.OPENAI_BASE_URL || "https://api.openai.com/v1"; const apiKey = process.env.OPENAI_API_KEY; if (!apiKey) { throw ...[truncated 4207 chars]- Remediation
View remediation
