T09 · Insecure Skill Coding Practices
- Location
scripts/run.sh:220- Finding
Runtime administrator token can be disclosed to an attacker-controlled endpoint
- Content
View full analysis
/dev/null 2>&1; then printf '%s\n' "$candidate" return 0 fi done local fallback="${preferred:-${MX_APP_RUNTIME_BASE_URL:-${RPA_RUNTIME_BASE_URL:-$(pref_get defaultLocalBaseUrl)}}}" if [[ -n "$fallback" ]]; then printf '%s\n' "$fallback" else printf '%s\n' "${DEFAULT_RUNTIME_BASE_URLS[0]}" fi } ``` The automatically discovered administrator token is then attached to a request to that URL: ```bash fetch_trigger_services() { local base_url="$1" local token="$2" curl -fsS \ -H "Authorization: Bearer $token" \ "$base_url/trigger-services" } ``` ```bash LOCAL_RUNTIME_TOKEN="" EFFECTIVE_LOCAL_BASE_URL="" if [[ "$CONNECTION_MODE" == "local" || "$REFRESH_TRIGGERS" == "true" ]]; then LOCAL_RUNTIME_TOKEN="$(discover_runtime_admin_token "$APP_HOME")" ...[truncated 6170 chars]- Remediation
View remediation
