Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() except Exception as e: body_text = ""- Confidence
- 96% confidence
- Finding
- The code sends authentication material and user data to a URL derived from environment-controlled base URLs via requests.post(). If an attacker can influence LINKFOX_LOGIN_API_URL or LINKFOX_AGENT_USER_API_URL, SMS login codes, access tokens, refresh tokens, generated API keys, and related identifiers can be exfiltrated to an attacker-controlled server. In a skill environment, treating environment variables as trusted infrastructure is unsafe because they are an unverified external control plane.
