T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:45- Finding
Persistent dotenv Injection Can Redirect Authenticated API Requests
- Content
View full analysis
Vulnerability Details
File Location:
scripts/config.py:45-58,scripts/config.py:61-69; request sink atscripts/call_api.py:49-68
Vulnerability Type: Persistent configuration injection and credential disclosure
Risk Level: MediumVulnerable Code
python # scripts/config.py:45-58 def save_api_key_to_env(api_key: str) -> bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return Truepython # scripts/config.py:61-69 def set_api_key(api_key: str) -> bool: """设置API key并持久化到.env""" if not api_key or not api_key.strip(): return False api_key = api_key.strip() if not save_api_key_to_env(api_key): return False # 更新全局 settings 实例 settings.api_key = api_key return Truepython # scripts/config.py:10-15 model_config = SettingsConfigDict( env_prefix="XBY_GAOKAO_", env_file=".env", env_file_encoding="utf-8", extra="ignore", )python # scripts/call_api.py:49-68 url = f"{settings.base_url}/api" mcp_id = mcp_id or settings.mcp_id api_key = get_api_key() if not api_key: raise UpstreamError("API密钥未设置,请先调用 set_api_key()") headers = { "XBY-APIKEY": api_key, "func": tool_name, "mcpid": mcp_id, "Content-Type": "application/json", } t0 = time.time() try: resp = self._session.post( url=url, headers=headers, data=json.dumps(params) ...[truncated 2409 chars]- Remediation
View remediation
Remediation Suggestions
-
Apply strict API-key validation before persistence:
- Reject
\r,\n, NUL, control characters, and unexpected whitespace. - Enforce the provider's documented key length and character set.
- Fail closed when validation is unsuccessful.
- Reject
-
Do not build dotenv records through direct string interpolation. Use a dotenv serialization library that safely quotes values, or avoid dotenv persistence for secrets entirely.
-
Store credentials in an operating-system credential manager or managed secret store. If
.envremains necessary:- Create it with owner-only permissions such as
0600. - Ensure it is excluded from version control.
- Avoid storing unrelated configurable security boundaries in the same attacker-influenced file.
- Create it with owner-only permissions such as
-
Prevent endpoint redirection:
- Make the production API endpoint immutable.
- Require the
httpsscheme. - Enforce an exact hostname allowlist, such as
mcp.xiaobenyang.com. - Reject URLs containing user information, fragments, unexpected ports, or non-HTTPS schemes.
-
Add regression tests using keys containing CRLF sequences, dotenv syntax, quotes, Unicode separators, and NUL characters. Verify that invalid values are rejected and cannot alter any
XBY_GAOKAO_*setting.
-
