T09 · Insecure Skill Coding Practices
- Location
SKILL.md:17- Finding
API Credential Exposure Through URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 17–20
Vulnerability Type: API credential exposure through query-string authentication
Risk Level: MediumVulnerable Code
markdown ## Format Autentikasi **PENTING:** Gunakan query parameter, BUKAN header Authorization.text https://api.goapi.io/stock/idx/companies?api_key={GOAPI_KEY}The same credential-bearing URL pattern is also used in the endpoint examples on lines 26, 31, 36, and 41.
Technical Analysis
The skill explicitly instructs the agent to place
GOAPI_KEYin the URL query string instead of an authorization header. Although HTTPS encrypts the request in transit, query strings are commonly retained by HTTP clients, reverse proxies, access logs, monitoring systems, debugging tools, exception reports, and agent/tool transcripts.Consequently, a request URL recorded by any intermediary may expose the complete API credential. An attacker with access to such records could extract and replay the key without needing to compromise the encrypted network connection.
Attack Path
- A user configures a valid
GOAPI_KEY. - The skill constructs a request such as:
https://api.goapi.io/stock/idx/companies?api_key=SECRET_VALUE. - The complete URL is captured in client history, proxy logs, observability telemetry, debugging output, error reports, or tool transcripts.
- An attacker or unauthorized log reader obtains the recorded URL.
- The attacker extracts
SECRET_VALUEand submits requests directly to GoAPI. - The attacker continues using the credential until it is revoked, rotated, or otherwise expires.
Impact Assessment
Exploitation can grant unauthorized use of the affected GoAPI account within the permissions and limits assigned to the exposed key. This may allow an attacker to retrieve API data, consume request quotas, cause service disruption through quota exhaustion, or incur account charges ...[truncated 175 chars]
- A user configures a valid
- Remediation
View remediation
Remediation Suggestions
- Prefer an
Authorizationheader or another non-URL authentication mechanism supported by GoAPI. - If GoAPI only supports query-string authentication, ensure clients, proxies, monitoring systems, and agent tools redact the
api_keyparameter before recording URLs. - Never display or return fully expanded credential-bearing URLs in agent responses, errors, or diagnostic output.
- Use narrowly scoped, short-lived API keys where the provider supports them.
- Apply strict access controls and short retention periods to logs that may contain request metadata.
- Configure quota and billing alerts to detect unauthorized use promptly.
- Rotate the key immediately if a complete request URL has been logged or otherwise disclosed.
- Prefer an
