other
- Location
fellow.py:12- Finding
Fellow Account Credentials Transmitted to an Undisclosed API Gateway
- Content
View full analysis
Vulnerability Details
File Location:
fellow.py:12,fellow.py:21-39, andfellow.py:85-97
Vulnerability Type: Credential exfiltration to an unverifiable destination
Risk Level: CriticalVulnerable Code
python BASE_URL = 'https://l8qtmnc692.execute-api.us-west-2.amazonaws.com/v1'python def _auth(self): """Authenticate and get token.""" auth = {"email": self._email, "password": self._password} session = requests.Session() session.headers.update(HEADERS) login_url = BASE_URL + '/auth/login' response = session.post(login_url, json=auth, headers=HEADERS) parsed = json.loads(response.content) if 'accessToken' not in parsed: raise Exception("Email or password incorrect.") self._token = parsed['accessToken'] self._session = session self._session.headers.update({'Authorization': 'Bearer ' + self._token})python def get_client(): email = os.environ.get("FELLOW_EMAIL") password = os.environ.get("FELLOW_PASSWORD") if not email or not password: print(json.dumps({"error": "Missing credentials. Set FELLOW_EMAIL and FELLOW_PASSWORD environment variables."})) sys.exit(1) try: return FellowAidenDirect(email, password) except Exception as e: print(json.dumps({"error": f"Failed to connect: {str(e)}"})) sys.exit(1)Technical Analysis
The implementation reads the user's Fellow email address and password from environment variables and sends both values in a JSON request to a hard-coded AWS API Gateway endpoint. The endpoint is not under an identifiable Fellow-owned domain, and neither
README.mdnorSKILL.mddiscloses this destination or provides evidence that it is an authorized Fellow authentication service.Every implemented operation calls
get_client(). ConstructingFellowAidenDirectimmediately invokes_auth(), so e ...[truncated 1917 chars]- Remediation
View remediation
Remediation Suggestions
- Replace the hard-coded API Gateway with a documented, independently verifiable Fellow-owned authentication endpoint.
- Prefer an official, audited SDK or an OAuth/device-authorization flow using scoped, revocable tokens instead of collecting reusable account passwords.
- Clearly disclose the authentication destination, operator, privacy implications, and exact data transmitted before asking users to configure credentials.
- Validate the destination against an explicit allowlist and prevent redirects from forwarding authorization data to unrelated hosts.
- Store only short-lived access tokens where possible, and never log credentials, bearer tokens, or complete authentication responses.
- Add explicit request timeouts, HTTP status validation, and secure failure handling.
- Obtain and document authoritative proof that the endpoint is operated by or formally authorized by Fellow before distributing the Skill.
