T09 · Insecure Skill Coding Practices
- Location
SKILL-INFO.md:159- Finding
Hardcoded Bearer Credential in an External Upload Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL-INFO.md, lines 159-163
Vulnerability Type: Hardcoded authentication credential
Risk Level: HighVulnerable Code
bash curl -X POST "https://xiaping.coze.site/api/upload" \ -H "Authorization: Bearer agent-world-e4a41c3dd47b88c55af0729dbb98cff4d98efd3cbce461b0" \ -F "file=@agent-migration-pack.zip" \ -F "skill_id=c7363f71-212f-4b34-9551-f72bf5d47044" \ -F "changelog=v1.0.5更新内容"Technical Analysis
The documentation contains a plaintext bearer token that appears to authenticate requests to an external upload API. Anyone with read access to the repository, distributed skill package, generated documentation, logs, or cached audit output can recover and attempt to reuse this credential.
Bearer credentials grant access based solely on possession. Unlike an illustrative placeholder, this value has the structure of a concrete credential and is directly embedded in an executable command. The project also supplies the associated API endpoint and skill identifier, making attempted reuse straightforward.
Whether the credential is currently valid cannot be established through static analysis. Nevertheless, publishing a potentially active secret is itself an insecure credential-management practice and requires immediate revocation.
Attack Path
- An attacker obtains a copy of the public or internally distributed skill package.
- The attacker extracts the bearer token, endpoint, and skill identifier from
SKILL-INFO.md. - The attacker prepares a modified or malicious archive named
agent-migration-pack.zip. - The attacker reproduces the documented
curlrequest with the exposed credential. - If the API accepts the token and does not independently enforce ownership or artifact signing, the attacker uploads or replaces content associated with the referenced skill.
- Downstream users may then receive unauthorized content under the identit ...[truncated 607 chars]
- Remediation
View remediation
Remediation Suggestions
-
Revoke and rotate the exposed token immediately; deleting it from the current revision is insufficient because it may remain in repository history, caches, and released packages.
-
Review external API audit logs for uploads or other requests made with this credential.
-
Replace the literal value with a non-secret placeholder, such as:
bash curl -X POST "https://xiaping.coze.site/api/upload" \ -H "Authorization: Bearer ${XIAPING_UPLOAD_TOKEN}" \ -F "file=@agent-migration-pack.zip" \ -F "skill_id=${SKILL_ID}" \ -F "changelog=${CHANGELOG}" -
Obtain the token at runtime from an approved secret manager or protected environment variable. Never store it in documentation, templates, examples, archives, or source control.
-
Configure a short expiration period, minimum required scope, per-publisher authorization, and artifact-signing checks on the server.
-
Add automated secret scanning to pre-commit hooks and CI, including repository-history scanning.
-
Purge the credential from prior commits and released archives after rotation.
-
