T09 · Insecure Skill Coding Practices
- Location
scripts/search.py:14- Finding
Hard-Coded Bearer Token Exposes a Reusable API Credential
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search.py, line 14
Vulnerability Type: Hard-coded secret
Risk Level: HighVulnerable Code
python DEFAULT_SEARCH_TOKEN = "eyJhbGciOiJSUzI1NiIsImtpZCI6ImQ0MWIxZTA3LWU0NjgtNGVkNS05ZGIwLWY0NjViMGQ5MmU4ZiJ9.eyJpc3MiOiJodHRwczovL2FwaS5jb3plLmNuIiwiYXVkIjpbIk5uZUN2TGgwaGl4RHFuNlk4ZTJ2YnI2aEFZenJWd1JIIl0sImV4cCI6ODIxMDI2Njg3Njc5OSwiaWF0IjoxNzcyNjAxMTEwLCJzdWIiOiJzcGlmZmU6Ly9hcGkuY296ZS5jbi93b3JrbG9hZF9pZGVudGl0eS9pZDo3NjEzMjU3NTc2OTE4MDI0MjMzIiwic3JjIjoiaW5ib3VuZF9hdXRoX2FjY2Vzc190b2tlbl9pZDo3NjEzMjYzNzk4ODE1Njg2NzA4In0.B5SHufj3jzhI54uc3218woi1KS6606Wg6Lelj6fK11rTQK8AibKkgjitbp1guhZNE8TpPyE-nFPH9cKYHL8G94t_2V0u3TbOw6na1AgbGKEQTpyokI_7QDqwIM0o82P8VLl_cYfpHbuglhS39MTt7gw8UI2LgdAaDC8QfoZwKJZ3CQvslOrOqf2bxxSTZ7XOpizB4ShajdbbvzJywCe3EjUh6rYvJEx_i_HPBM--APB09yMUVCzQrYdo5MTrkf4ZMK-Hej3huJJXkBwX0B-symujbxJLCi5EckAoP7uQLIuna_W6JypCtb7SdofJkK3oFYgek9iYg9DlKiC1TC-BGg"Technical Analysis
The source package embeds a bearer token as its default authentication credential. The script reads
UNIVERSAL_SEARCH_TOKENfrom the environment when available, but otherwise automatically uses the distributed token:python SEARCH_TOKEN = os.environ.get("UNIVERSAL_SEARCH_TOKEN", DEFAULT_SEARCH_TOKEN)It subsequently places that credential into the HTTP
Authorizationheader:python SEARCH_HEADERS = { "Authorization": f"Bearer {SEARCH_TOKEN}", "Content-Type": "application/json", }Bearer tokens grant access based solely on possession. Any person who can download, inspect, or otherwise obtain the skill package can extract the token without needing to compromise a running system. Environment-variable override support does not protect the embedded credential or prevent its reuse outside this script.
Attack Path
- An attacker obtains the publicly distributed skill package or its source code.
- The attacker opens
scripts/search.pyand copiesDEFAULT_SEARCH_TOKENfrom line 14. - The a ...[truncated 1257 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke the exposed token immediately and issue a replacement, because removing it from a later version does not invalidate copies already distributed.
- Remove
DEFAULT_SEARCH_TOKENfrom the source and requireUNIVERSAL_SEARCH_TOKENto be explicitly configured. - Fail securely with a clear error when the environment variable is missing, for example:
python SEARCH_TOKEN = os.environ.get("UNIVERSAL_SEARCH_TOKEN") if not SEARCH_TOKEN: raise RuntimeError("UNIVERSAL_SEARCH_TOKEN is required")- Provision a separate credential for each user, deployment, or workload rather than sharing one token across all installations.
- Use short-lived, narrowly scoped credentials restricted to the required API, audience, and operations.
- Store credentials in an appropriate secret manager or protected runtime configuration rather than source control, documentation, package metadata, or default configuration.
- Review repository and package history for prior exposure, and rotate any related credentials that may have been derived from or distributed with this token.
- Enable server-side rate limiting, usage alerts, and audit logging to identify historical or future misuse.
- Add automated secret scanning to source-control and release pipelines to prevent credential-bearing artifacts from being published.
