Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() except Exception as e: body_text = ""- Confidence
- 93% confidence
- Finding
- The POST target URL is derived from environment-controlled base URLs, and this function can send sensitive data such as phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys to whatever endpoint those variables specify. In a skill execution environment where env vars may be platform-controlled or attacker-influenced, this creates an SSRF/exfiltration channel that can silently redirect credential-bearing requests off the intended LinkFox infrastructure.
