T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_samples.py:215- Finding
Implicit Credential Transmission During General Cryptocurrency Fetches
- Content
View full analysis
JSONList: url = ( "https://cryptopanic.com/api/developer/v2/posts/?" f"auth_token={token}&public=true¤cies={base_symbol}&kind={kind}" ) try: resp = requests.get(url, timeout=10) except requests.RequestException: raise RuntimeError("CryptoPanic request failed") from None ``` ### Technical Analysis The general `fetch_crypto()` workflow automatically reads the `CRYPTOPANIC_TOKEN` environment variable and transmits it whenever the variable is present. This behavior occurs even when the caller only requests cryptocurrency prices or technical indicators and has not explicitly requested news. The transmission destination is the fixed CryptoPanic HTTPS endpoint, and the token is necessary when news is explicitly requested. Therefore, this is not evidence of attacker-controlled exfiltration. However, implicitly accessing and transmitting a credential exceeds the minimum privileges required for the general cryptocurrency-data workflow and conflicts with the documentation stating that the token should only be used when the user requests cryptocurrency news. The token is also embedded in the URL query string. Although HTTPS protects it in transit, complete URLs can be retained by local HTTP debugging tools, proxies, monitoring systems, or observability infrastructure. ### Attack Path 1. A user places a valid CryptoPanic token in ...[truncated 1142 chars]- Remediation
View remediation
