T09 · Insecure Skill Coding Practices
- Location
scripts/prediction_market_client.py:78- Finding
Bearer API Key May Be Disclosed Through Cross-Origin HTTP Redirects
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent read-only prediction-market API client, but it handles a paid API key and wallet identifiers with enough disclosure and credential-safety gaps that users should review it before installing.
Install only if you are comfortable sending your AIsa API key and any wallet addresses or market query parameters to api.aisa.one. Use a limited or revocable API key, monitor usage costs, and consider asking the publisher to add same-origin redirect protection and clearer privacy/permission metadata.
scripts/prediction_market_client.py:78Bearer API Key May Be Disclosed Through Cross-Origin HTTP Redirects
The skill requires an environment secret (AISA_API_KEY) and makes outbound network requests, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege enforcement and transparency for users and runners, making it easier for a host environment to grant broader capabilities than the skill actually needs.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class PredictionMarketClient:
"""Cross-Platform Prediction Market Data - AIsa API Client."""
BASE_URL = "https://api.aisa.one/apis/v1"
def __init__(self, api_key: Optional[str] = None):
self.api_key = api_key or os.environ.get("AISA_API_KEY")
The client sends wallet addresses, position/P&L queries, and related market parameters to a third-party API without any explicit disclosure, consent prompt, or privacy notice in the tool itself. In an agent skill context, users may reasonably assume inputs are handled locally, so silent transmission of financial-identifying data can create privacy and metadata exposure risks.
The client automatically reads AISA_API_KEY from the environment, which is a sensitive credential access pattern covered by this rule. While the exception message mentions the variable when missing, there is no proactive user-facing warning or disclosure in normal operation that the script will consume a secret from the environment and use it for outbound authenticated requests.
No suspicious patterns detected.