T09 · Insecure Skill Coding Practices
- Location
skills/smyx_common/scripts/util.py:414- Finding
Workspace API-key file content disclosed as an identity over plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
skills/smyx_common/scripts/util.py:414-420, 458-466, 550-561;skills/smyx_common/scripts/config.yaml:15;skills/smyx_common/scripts/config-dev.yaml:2-4
Vulnerability Type: Sensitive information disclosure over an unencrypted network connection
Risk Level: HighVulnerable Code
python @classmethod def get_api_key_file_open_id(cls): """Read the internal identity value from workspace data/smyx-api-key.txt.""" api_key_path = os.path.join(cls.get_workspace_data_dir(), "smyx-api-key.txt") try: if not os.path.exists(api_key_path): return None with open(api_key_path, "r", encoding="utf-8") as f: value = f.read().strip() return value or Nonepython def resolve_current_open_id(cls, open_id=None, use_current=True): """Resolve and initialize the current open-id.""" resolved_open_id = (open_id or "").strip() if isinstance(open_id, str) else open_id if not resolved_open_id and use_current: resolved_open_id = ConstantEnum.CURRENT__OPEN_ID or ConstantEnum.CURRENT__USER_NAME if not resolved_open_id: resolved_open_id = cls.get_api_key_file_open_id() if not resolved_open_id: resolved_open_id = cls.get_or_create_default_open_id()python def _get_or_create_user(username): _url = ApiEnum.BASE_URL_HEALTH + "/sys/phoneLogin" open_id = username _data = { "silent": 1, "register": 1, "openId": open_id, "mobile": username, "source": ConstantEnum.DEFAULT__SKILL_HUB_NAME } try: _response = requests.post(_url, json=_data)The selected configuration environment is:
yaml env: devIts effective endpoints are:
yaml ApiEnum: base-url-open-api: "http://192.168.1.234:9601/smyx-open-api" base-url-open-h5: "http://192.168.1.234:4100 ...[truncated 2275 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the fallback that reads identity information from
smyx-api-key.txt. - Store API credentials and user identifiers in separate files or credential-store entries with unambiguous names and schemas.
- Use an OS-backed credential store for API keys rather than a plaintext workspace file.
- Require HTTPS for authentication endpoints and reject any
http://destination before sending data. - Replace the checked-in development environment with a production-safe default.
- Restrict remote destinations to an explicit allowlist of trusted hostnames; do not use mutable private-network addresses for authentication.
- Send only the minimum required identifier and do not duplicate it into both
openIdandmobile. - Obtain explicit, informed consent before transmitting a locally stored identifier.
- Rotate any credentials that may already have been stored in
smyx-api-key.txtand transmitted by this implementation. - Add automated tests confirming that API-key file contents can never enter request bodies, query parameters, or logs.
- Remove the fallback that reads identity information from
