T09 · Insecure Skill Coding Practices
- Location
scripts/twitter_oauth_client.py:458- Finding
AISA API Key Exposed in Command Output and Redundantly Included in Request Bodies
- Content
View full analysis
None: config = load_config(args) payload = {"aisa_api_key": config["aisa_api_key"]} result = send_json_request( f"{config['base_url']}/twitter/auth_twitter", payload, timeout=config["timeout"], aisa_api_key=config["aisa_api_key"], ) if result.get("ok") is False: print(json.dumps(result, indent=2, ensure_ascii=False)) sys.exit(1) auth_url = (result.get("data") or {}).get("auth_url") output = { "ok": result.get("code") == 200 and bool(auth_url), "aisa_api_key": config["aisa_api_key"], "authorization_url": auth_url, "raw_response": result, } print(json.dumps(output, indent=2, ensure_ascii=False)) ``` The posting path also includes the credential in returned result structures: ```python if result.get("ok") is False or result.get("code") != 200: return { "ok": False, "aisa_api_key": config["aisa_api_key"], "is_thread": should_thread, "total_chunks": len(chunks), "failed_at_chunk": index + 1, "results": publish_results, } latest_tweet_id = extract_tweet_id(result) if not latest_tweet_id: return { "ok": False, "aisa_api_key": config["aisa_api_key"], "is_thread": should_thread, "total_chunks": len(chunks), "failed_at_chunk": index + 1, "error": "Missing tweet_id in relay response.", "results": publish_results, } ``` ### Technical Analysis The client reads `AISA_API_KEY` from the environment and correctly uses it as a Bearer credential: ```python headers = { "Authorization": f"Bearer {aisa_api_key}", "User-Agent": DE ...[truncated 2664 chars]- Remediation
View remediation
``` 3. If backend compatibility temporarily requires body authentication, update the backend first and then remove the duplicate field from the client. 4. Add centralized recursive output redaction before serializing responses. At minimum, redact fields named: - `aisa_api_key` - `authorization` - `token` - `access_token` - `refresh_token` 5. Do not return complete raw relay responses when they may contain credentials or OAuth state. Construct a minimal allowlisted response containing only required fields such as status, authorization URL, tweet ID, and error message. 6. Add automated tests asserting that a sentinel API key never appears in: - Standard output. - Standard error. - Returned result dictionaries. - JSON request bodies. - Multipart form fields. 7. Rotate any API key that has already been processed by this version if command output may have been logged or retained. ]]>
