T09 · Insecure Skill Coding Practices
- Location
server.py:11- Finding
GitHub Access Token Exposed to Browser Content
- Content
View full analysis
No GitHub token. Run: gh auth login
') return html = serve_html(token) self.send_response(200) self.send_header('Content-Type', 'text/html') self.send_header('Content-Length', len(html)) self.end_headers() self.wfile.write(html.encode()) ``` The legacy Python implementation has the equivalent behavior: ```python const TOKEN = "{token}"; ``` ```python class BlogStudioHandler(BaseHTTPRequestHandler): def do_GET(self): token = get_gh_token() if not token: self.send_response(401) self.send_header('Content-Type', 'text/html') self.end_headers() self.wfile.write(b'GitHub token not found. Run: gh auth login
') return self.send_response(200) self.send_header('Content-Type', 'text/html') self.end_headers() self.wfile.write(make_html(token).encode()) ``` ### Technical Analysis The server obtains the authenticated user's GitHub token by executing `gh a ...[truncated 1991 chars]- Remediation
View remediation
` - `DELETE /api/posts/` 4. Validate repository paths against explicit content directories and accepted file extensions. 5. Generate a random per-launch session secret and require it on state-changing requests. 6. Validate `Origin` and `Host` headers and implement CSRF protection. 7. Return `Cache-Control: no-store` for all authenticated application responses. 8. Use a fine-grained GitHub token restricted to the required repository and Contents permission. 9. Add explicit route handling so arbitrary GET paths cannot retrieve application credentials. 10. Revoke and rotate any token that may already have been exposed through this design. ]]>
