T09 · Insecure Skill Coding Practices
- Location
scripts/common.sh:5- Finding
API Signature Transmitted over Plaintext HTTP and Exposed in the Request URL
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 fi ``` 6. Redact signatures from debug output, telemetry, error reports, and agent tool transcripts. 7. Rotate any signature that has already been used through these HTTP endpoints, because prior interception or logging cannot be ruled out. 8. Consider short-lived, narrowly scoped credentials and server-side rate limits to reduce the impact of credential replay. ]]>
