T09 · Insecure Skill Coding Practices
- Location
scripts/sparki_video_editor.py:68- Finding
Unvalidated API endpoint permits credential and video disclosure to arbitrary hosts
- Content
View full analysis
SparkiConfig: file_path = Path(config_file).expanduser() if config_file else DEFAULT_CONFIG_FILE file_values = load_env_file(file_path) api_key = get_env_value("SPARKI_API_KEY", file_values) if not api_key: raise SparkiError( f"SPARKI_API_KEY is not set. Configure it in the environment or {file_path}." ) api_url = get_env_value("SPARKI_API_URL", file_values, DEFAULT_API_URL).rstrip("/") output_dir_raw = get_env_value("SPARKI_OUTPUT_DIR", file_values, DEFAULT_OUTPUT_DIR) output_dir = Path(output_dir_raw).expanduser() return SparkiConfig( api_key=api_key, api_url=api_url, output_dir=output_dir, config_file=file_path, ``` ```python def api_request( method: str, url: str, api_key: str, payload: dict[str, Any] | None = None, ) -> dict[str, Any]: body = b"" headers = { "X-API-Key": api_key, "User-Agent": DEFAULT_USER_AGENT, "Accept": "application/json", } if payload is not None: body = json.dumps(payload).encode("utf-8") headers["Content-Type"] = "application/json" parsed = urlparse(url) path = parsed.path if parsed.query: path = f"{path}?{parsed.query}" connection_class = HTTPSConnection if parsed.scheme == "https" else HTTPConnection connection = connection_class(parsed.hostname, parsed.port, timeout=60) try: connection.request(method, path, body=body, headers=headers) ``` ```python def upload_asset(config: SparkiConfig, video_path: Path) -> str: ...[truncated 4283 chars]- Remediation
View remediation
