T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_common.py:15- Finding
Environment-Controlled API Endpoints Can Redirect Authentication Credentials
- Content
View full analysis
dict: """Call the Temu gateway API; a LinkFox user token is required.""" linkfox_token = get_linkfox_token(linkfox_params) data = json.dumps(body, ensure_ascii=False).encode("utf-8") req = Request( url, data=data, headers=build_gateway_headers(linkfox_token), method="POST", ) ``` The onboarding subsystem exposes the same class of behavior for additional credentials: ```python def _agent_base() -> str: return _env_base("LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY") def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base("LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com") ``` ```python def _http_post(url: str, body: dict, headers: dict, timeout: int = 30) -> dict: """Generic requests POST, returning JSON or {_error, _body}.""" try: _require_requests() except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() ``` ### Technical Analysis The Skill legitimately needs to transmit a LinkFox API key and Temu access token ...[truncated 2261 chars]- Remediation
View remediation
