T09 · Insecure Skill Coding Practices
- Location
thought_retriever.py:31- Finding
Hard-Coded API Credential Exposed in Source Code
- Content
View full analysis
`. 4. If the key remains valid, requests are billed to or attributed to the credential owner. 5. The attacker can continue using the credential until it is revoked, expires, or is restricted by the provider. ### Impact Assessment If active, the exposed key grants the attacker the API privileges assigned to that credential. Potential impact includes: - Unauthorized use of the associated LLM API. - Consumption of account quota and generation of charges. - Service disruption through ...[truncated 347 chars]- Remediation
View remediation
