Tainted flow: 'url' from os.getenv (line 231, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
"title": "OpenClaw Skill Payment", "description": "Polymarket Movers x3", } r = requests.post(url, json=body, headers=headers, timeout=20) if r.status_code not in (200, 201): raise HTTPException(status_code=502, detail="SkillPay create charge failed") data = r.json()- Confidence
- 96% confidence
- Finding
- r = requests.post(url, json=body, headers=headers, timeout=20)
