T09 · Insecure Skill Coding Practices
- Location
scripts/lib/monzo.sh:8- Finding
Unrestricted API Base Override Can Exfiltrate OAuth Secrets and Bearer Tokens
- Content
View full analysis
&2 return 1 fi local response response=$(curl -s -X POST "$MONZO_API_BASE/oauth2/token" \ --data-urlencode "grant_type=refresh_token" \ --data-urlencode "client_id=$CLIENT_ID" \ --data-urlencode "client_secret=$CLIENT_SECRET" \ --data-urlencode "refresh_token=$REFRESH_TOKEN") ``` `scripts/lib/monzo.sh:168-189`: ```bash # Make authenticated API call # Usage: monzo_api_call GET /path [--data "key=value"] monzo_api_call() { local method="$1" local path="$2" shift 2 # Check token expiry before making call monzo_check_expiry local url="$MONZO_API_BASE$path" local response local http_code # Make the API call if [[ "$method" == "GET" ]]; then response=$(curl -s -w "\n%{http_code}" \ -H "Authorization: Bearer $ACCESS_TOKEN" \ "$url" "$@") else response=$(curl -s -w "\n%{http_code}" -X "$method" \ -H "Authorization: Bearer $ACCESS_TOKEN" \ "$url" "$@") fi ``` `scripts/setup.sh:17-20`: ```bash SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" CREDENTIALS_DIR="${OPENCLAW_CREDENTIALS_DIR:-${CLAWDBOT_CREDENTIALS_DIR:-${HOME}/.openclaw/credentials}}" CREDENTIALS_FILE="${CREDENTIALS_DIR}/monzo.json" MONZO_API_BASE="${MONZO_API_BASE:-https://api.monzo.com}" ``` `scripts/setup.sh:439-444`: ```bash TOKEN_RESPONSE=$(curl -s -X POST "$MONZO_API_BASE/oauth2/token" \ --data-urlencode "grant_typ ...[truncated 2648 chars]- Remediation
View remediation
