T09 · Insecure Skill Coding Practices
- Location
scripts/query_insights.sh:4- Finding
API Token Disclosure Through an Unrestricted Search API Base URL
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 ;; esac ``` 3. Require HTTPS and reject embedded credentials, unexpected ports, IP-address substitutions, and hostname suffix tricks. 4. Avoid following redirects for authenticated requests unless redirects are strictly necessary. Remove `--location`, or validate each redirect target and ensure authentication headers cannot cross trusted-origin boundaries. 5. Consider loading the token only after endpoint validation so the secret is never placed into a request prepared for an untrusted destination. 6. Rotate any token that may already have been used while `BASE_URL` pointed to an untrusted host, and review API access logs for misuse. ]]>
