T09 · Insecure Skill Coding Practices
- Location
src/browser/secure-session.ts:299- Finding
Vault credentials may be injected into an untrusted origin after a redirect
- Content
View full analysis
{ if (!page) return; try { const usernameSelectors = [ 'input[type="email"]', 'input[name="email"]', 'input[name="username"]', 'input[id="username"]', 'input[id="login"]', 'input[name="login"]' ]; for (const selector of usernameSelectors) { const field = await page.$(selector); if (field) { await field.fill(username); break; } } const passwordInput = await page.$('input[type="password"]'); if (passwordInput) { await passwordInput.fill(password); logAction('fill_password', { method: 'vault_injected' }, { userApproved: true }); } await takeScreenshot('login'); } catch (e) { throw new Error(`Failed to fill login ...[truncated 1569 chars]- Remediation
View remediation
