T09 · Insecure Skill Coding Practices
- Location
scripts/posta-api.sh:12- Finding
Configurable API Origin Can Exfiltrate Posta Credentials and Bearer Tokens
- Content
View full analysis
&2 echo "Searched: env vars, ~/.zshrc, ~/.bashrc, .env files, ~/.posta/credentials" >&2 return 1 fi local response response=$(curl -sf -X POST "${POSTA_BASE_URL}/auth/login" \ -H "Content-Type: application/json" \ -d "{\"email\": \"${POSTA_EMAIL}\", \"password\": \"${POSTA_PASSWORD}\"}") ``` ```bash posta_api() { local method="$1" local endpoint="$2" local body="${3:-}" local token local tmpfile="/tmp/.posta_response_$$" token=$(posta_get_token) local args=( -s -X "$method" -H "Authorization: Bearer ${token}" -H "Content-Type: application/json" -o "$tmpfile" -w "%{http_code}" ) if [[ -n "$body" ]]; then args+=(-d "$body") fi local http_code http_code=$(curl "${args[@]}" "${POSTA_BASE_URL}${endpoint}") ``` ### Technical Analysis `POSTA_BASE_URL` is accepted directly from the process environment without validating its scheme or host. Both legacy Posta email/password credentials and bearer tokens are subsequently transmitted to that destination. The override may be useful for development, but allowing an arbitrary origin in the normal authentication path exceeds the minimum privilege required by the production Skill. In particular, the implementation does not require HTTPS and does not restrict the host to the documented `api.getposta.app` service. This is not an unexplained network transmission: authentication and API calls are necessary for the Skill. The vulnerability is that the security-sensitive destination can be changed without a separate, explicit de ...[truncated 1025 chars]- Remediation
View remediation
