Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() except Exception as e: body_text = ""- Confidence
- 96% confidence
- Finding
- The code builds request destinations from environment-controlled base URLs and then sends sensitive authentication material such as access tokens, API keys, phone numbers, SMS codes, and group identifiers to those endpoints. If an attacker can influence environment variables in the skill runtime, they can redirect these requests to an attacker-controlled host and exfiltrate credentials or intercept login and payment flows.
