Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() except Exception as e: body_text = ""- Confidence
- 91% confidence
- Finding
- The POST target is derived from environment-controlled base URLs, and the request can include sensitive data such as phone numbers, SMS codes, access tokens, refresh tokens, generated API keys, and account metadata. If an attacker can influence environment variables in the skill runtime, they can redirect these requests to attacker-controlled infrastructure and exfiltrate credentials or manipulate onboarding flows.
