T09 · Insecure Skill Coding Practices
- Location
toolkit/api_client.py:40- Finding
Volcengine API Key Disclosure Through an Unrestricted Base URL
- Content
View full analysis
None: """Load configuration from environment variables.""" env_mappings = { "ARK_API_KEY": "api_key", "VOLCENGINE_BASE_URL": "base_url", "VOLCENGINE_TIMEOUT": "timeout", "VOLCENGINE_MAX_RETRIES": "max_retries", "VOLCENGINE_OUTPUT_DIR": "output_dir", } for env_var, config_key in env_mappings.items(): value = os.getenv(env_var) if value is not None: if config_key == "timeout": value = int(value) elif config_key == "max_retries": value = int(value) self._config[config_key] = value ``` ```python # toolkit/api_client.py:40-60 self.base_url = self.config.get_base_url() self.timeout = self.config.get_timeout() self.max_retries = self.config.get("max_retries", 3) self.api_key = self.config.get_api_key() if not self.api_key: raise AuthenticationError( message="API key not configured", context={"hint": "Set ARK_API_KEY environment variable or configure i ...[truncated 2264 chars]- Remediation
View remediation
