T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:44- Finding
Plaintext API Key Storage and Credential Exfiltration Through a Configurable API Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/config.py:11-20,scripts/config.py:44-61;scripts/call_api.py:51-79
Vulnerability Type: Plaintext credential storage and unsafe endpoint configurability
Risk Level: MediumVulnerable Code
scripts/config.py:11-20:python model_config = SettingsConfigDict( env_prefix="XBY_GAOKAO_", env_file=".env", env_file_encoding="utf-8", extra="ignore", ) # API configuration base_url: str = "https://mcp.xiaobenyang.com" mcp_id: str = "1820705335657482" api_key: str = ""scripts/config.py:44-61:python def save_api_key_to_env(api_key: str) -> bool: """Store the API key in the .env file.""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return Truescripts/call_api.py:51-79:python url = f"{settings.base_url}/api" mcp_id = mcp_id or settings.mcp_id api_key = get_api_key() if not api_key: raise UpstreamError("API密钥未设置,请先调用 set_api_key()") headers = { "XBY-APIKEY": api_key, "func": tool_name, "mcpid": mcp_id, "Content-Type": "application/json", } # data = {k: str(v) if v is not None else "" for k, v in params.items()} t0 = time.time() try: resp = self._session.post( url=url, headers=headers, data=json.dumps(params), ...[truncated 2862 chars]- Remediation
View remediation
Remediation Suggestions
- Make the production API endpoint immutable in normal operation, or validate it against an exact allowlist before attaching credentials. Require HTTPS and verify that the normalized hostname is exactly
mcp.xiaobenyang.com. - If custom endpoints are required for development, separate development credentials from production credentials and require an explicit trusted configuration mode. Never forward a production key to an arbitrary configured host.
- Store the API key in an operating-system keyring, managed secret store, or Agent-provided secret facility instead of a workspace file.
- If
.envstorage is unavoidable, create the file atomically with owner-only permissions such as0600, verify existing file ownership and permissions before writing, and reject symlinks. - Ensure
.envis excluded from version control, packaging, logs, backups, support bundles, and shared archives. Provide a.env.examplecontaining placeholders only. - Avoid retaining the key in more locations than necessary. Do not copy it into the process environment unless required, and provide a supported mechanism to revoke or remove a stored key.
- Add automated tests confirming that credentials are never sent when the URL has an unapproved scheme, hostname, port, user-information component, or redirect destination.
- Disable cross-origin redirects for authenticated API requests, or strip the credential header before any redirect is followed.
- Make the production API endpoint immutable in normal operation, or validate it against an exact allowlist before attaching credentials. Require HTTPS and verify that the normalized hostname is exactly
