Checked on v2.12.0 and main at 3527006, --no-llm.
behavioral_taint_tracking._NETWORK_OUTPUT_SINKS includes urllib.request.urlopen but not OpenerDirector.open. This is reported as TT3:
req = urllib.request.Request(URL, headers={"Authorization": "Bearer " + os.environ["API_KEY"]})
urllib.request.urlopen(req)
The same request sent through an opener is not:
urllib.request.build_opener().open(req)
So a common hardening step (an opener with a no-redirect handler, so the Authorization header cannot follow a redirect to another origin) silences the finding, and any skill can send an environment credential out this way without TT3 firing.
Checked on v2.12.0 and
mainat3527006,--no-llm.behavioral_taint_tracking._NETWORK_OUTPUT_SINKSincludesurllib.request.urlopenbut notOpenerDirector.open. This is reported as TT3:The same request sent through an opener is not:
So a common hardening step (an opener with a no-redirect handler, so the Authorization header cannot follow a redirect to another origin) silences the finding, and any skill can send an environment credential out this way without TT3 firing.