External Script Fetching
- Category
- Supply Chain
- Confidence
- 91% confidence
- Finding
The health-check workflow sends a bearer token to external endpoints using
curl, including a playbook endpoint whose response is piped into Python for processing. Although this is framed as diagnostics, it normalizes transmitting a reusable API credential to a third-party service without strong safeguards, and any compromise, spoofing, logging leak, or misconfiguration could expose the token and enable unauthorized use of the user's Cue account.- Content
bash CUE_KEY=$(python3 -c "import json;print(json.load(open('$HOME/.cue/config.json'))['api_key'])" 2>/dev/null || echo "$CUE_API_KEY") echo "=== 1/3 API Key ===" && [ -n "$CUE_KEY" ] && echo "已配置" || echo "未配置!" echo "=== 2/3 Cue 服务 ===" && curl -sS --max-time 10 "https://cuecue.cn/api/health" -H "Authorization: Bearer $CUE_KEY" echo "=== 3/3 搭子 ===" && curl -sS --max-time 10 "https://cuecue.cn/api/playbook" -H "Authorization: Bearer $CUE_KEY" | python3 -c "import sys,json;scenes=json.load(sys.stdin).get('data',{}).get('scenes',[]);buddy=[b for s in scenes for b in s.get('buddies',[]) if b.get('title')=='热门赛道/ETF深度投研'];print(f'可用:{len(buddy)}个') if buddy else print('暂不可用')"
