T09 · Insecure Skill Coding Practices
- Location
config.json:2- Finding
Hard-Coded Tavily API Credential in Distributed Configuration
- Content
View full analysis
Vulnerability Details
File Location:
config.json:2
Vulnerability Type: Hard-coded service credential
Risk Level: HighVulnerable code:
json { "api_key": "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" }Technical Analysis
The project distributes a Tavily API key in plaintext within
config.json. Anyone able to download, clone, inspect, or otherwise access the Skill package can recover the credential without authentication or additional exploitation.The credential is operationally integrated into both implementations:
tavily.py:57-60loadsconfig.jsonand readsconfig["api_key"].tavily.py:79-88places the key in the JSON request body sent tohttps://api.tavily.com/search.tavily.ps1:44-45reads the same configuration and extracts$config.api_key.tavily.ps1:59-72places it in the request body sent to the Tavily API.
This crosses the trust boundary between a credential owner’s private service authorization and arbitrary recipients of the distributable project artifact. The evidence establishes insecure credential exposure, but does not establish credential theft or malicious intent by the project author.
Attack Path
- An attacker obtains the published Skill package or reads its project files.
- The attacker opens
config.jsonand copies the plaintext API key. - The attacker submits requests to the Tavily API using that key, either through the included scripts or a separate HTTP client.
- Tavily processes those requests under the exposed credential owner’s account until the key is revoked, expires, or reaches its service limits.
No execution of project code, local privilege, or modification of user-controlled input is required.
Impact Assessment
An attacker gains the service-level authorization associated with the exposed Tavily API key. This may permit unauthorized search requests, consumption of the account’s API quot ...[truncated 308 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke and rotate the exposed Tavily API key immediately.
- Remove the credential from the distributed package and all reachable version-control history.
- Replace
config.jsonwith a non-secret example such asconfig.example.json, containing only a placeholder value. - Load the credential from an environment variable or a protected, user-specific secret store rather than a project file.
- If file-based configuration remains supported, create it outside the package directory and apply owner-only permissions.
- Add
config.jsonand other secret-bearing local configuration files to ignore and packaging-exclusion rules. - Add automated secret scanning to the publication workflow and reject releases containing live credential patterns.
- Review Tavily usage records for unauthorized activity and apply service-side quota or scope restrictions where supported.
