Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() except Exception as e: body_text = ""- Confidence
- 93% confidence
- Finding
- The POST target URL is derived from environment-controlled base URLs, and this function sends authentication material and user data to that destination. If an attacker can influence environment variables in the skill runtime, they can redirect login or token traffic to an attacker-controlled server and exfiltrate SMS codes, access tokens, refresh tokens, and generated API keys.
