T09 · Insecure Skill Coding Practices
- Location
scripts/wechat_video_search.py:67- Finding
Bearer Token and Sensitive API Data Disclosed Through Debug Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it advertises, but it exposes the user's TikHub API token and search activity through normal debug output.
Review before installing. Use this only with a low-privilege TikHub token, avoid sensitive searches, and do not run this version where stdout or stderr is captured. Remove the token/debug prints and rotate any TikHub token used with this version in a logged environment.
scripts/wechat_video_search.py:67Bearer Token and Sensitive API Data Disclosed Through Debug Output
scripts/wechat_video_search.py:26Credential-Like Value Embedded in Source Code Comment
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
print("token",token)
print("DEBUG: url=", url)
try:
resp = requests.get(url, headers=headers, timeout=60)
print(f"DEBUG: status_code={resp.status_code}", file=sys.stderr)
print(f"DEBUG: response_text={resp.text[:500]}", file=sys.stderr)
resp.raise_for_status()
If the skill prints the TikHub API token, request URL, or portions of API responses, it can expose secrets and user query data to logs, terminals, screenshots, or downstream agents. This is especially dangerous because the token grants third-party API access and the search terms may contain sensitive investigative or personal information.
The script prints the full TikHub API token to stdout during normal execution with print("token", token). In agent, CI, or shared terminal contexts, stdout is often captured in logs, transcripts, or tool output, which can expose the credential to other users or systems and allow unauthorized API use.
Printing a sensitive API token without masking or warning is a direct secret exposure issue. Anyone with access to process output, shell history capture, notebook outputs, orchestration logs, or agent traces may recover the bearer token and impersonate the user against the third-party service.
The skill declares network, file-read, and environment-dependent behavior but does not declare any explicit tool scope or permissions. This weakens reviewability and containment: users and platforms cannot easily understand or restrict the skill’s access needs, increasing the chance of unintended data exposure or overly broad execution privileges.
The documentation instructs users to send both search keywords and an API token to a third-party service but does not clearly warn about privacy and data-sharing implications. Users may unknowingly transmit sensitive search terms, operational interests, or credentials to an external provider, creating confidentiality and compliance risks.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
from urllib.parse import quote
# API 端点(中国大陆使用新域名)
TIKHUB_SEARCH_URL = "https://api.tikhub.dev/api/v1/wechat_channels/fetch_search_latest"
def load_config():
The requests.get call sends the search keyword in the URL query string and the API token in the Authorization header to api.tikhub.dev. For a code file, external transmission of user data and credentials should have some visible disclosure, but the script provides no prompt or user-facing warning before making the network request.
The user-facing natural-language fields are written only in Chinese, which imposes a specific language/locale without indicating user choice or a justified region-specific constraint. The policy requires either an explicit language choice for users or clear documentation that the skill is intentionally region-specific.
This is a markdown file, so missing user warnings apply when the description omits warnings about behaviors affecting user data, privacy, or system integrity. The usage and API sections explain how to send keywords to a third-party service and retrieve video download links, but they do not disclose that user queries are transmitted externally or note any caution around handling returned media links.
The description states the skill requires bypassing network restrictions, and later notes prescribe a China-mainland-specific domain choice. This imposes a locale/network constraint without offering user choice or clearly framing it as an optional region-specific instruction.
This manifest description states the skill's general capability but does not define specific invocation phrases, scope limits, or exclusion conditions. In manifest files, missing trigger specificity can lead to overly broad or unintended activation if the host system uses the description for routing.
No suspicious patterns detected.