T09 · Insecure Skill Coding Practices
- Location
SKILL.md:28- Finding
API Key Solicitation Through Agent Conversation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:28-31;scripts/wechat_article_search_api.py:86-90
Vulnerability Type: Sensitive credential exposure through insecure operational guidance
Risk Level: MediumVulnerable Code and Instructions
SKILL.md:28-31:markdown ## 🔑 API Key Guidance Flow Before running, check the `BROWSERACT_API_KEY` environment variable. If not set, do not take other actions; request and wait for the user to provide it. **The Agent must inform the user**: > "Since you have not configured the BrowserAct API Key, please go to the [BrowserAct Console](https://www.browseract.com/reception/integrations) to get your Key."scripts/wechat_article_search_api.py:86-90:python if not api_key: print("\n[!] ERROR: BrowserAct API Key is missing.", flush=True) print("Please follow these steps:", flush=True) print("1. Go to: https://www.browseract.com/reception/integrations", flush=True) print("2. Copy your API Key.", flush=True) print("3. Provide it to me or set it as an environment variable (BROWSERACT_API_KEY).", flush=True)Technical Analysis
The Skill explicitly instructs the Agent to request and wait for the user's BrowserAct API key, while the script tells the user to “Provide it to me.” This encourages users to disclose a bearer credential through the Agent conversation.
API keys are sensitive authentication material. Secrets entered into an Agent conversation may be retained in conversation history, execution traces, application logs, monitoring systems, or model-provider telemetry. Anyone with access to those records could potentially recover and reuse the credential.
Conversational disclosure is not required for the declared functionality. The script already reads
BROWSERACT_API_KEYfrom the local environment:python api_key = os.getenv("BROWSERACT_API_KEY")Consequently, requesting the secret through the Agent ...[truncated 1931 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove all instructions asking users to provide or paste an API key into the Agent conversation.
-
Replace the guidance in
SKILL.mdwith instructions to configure the secret locally throughBROWSERACT_API_KEY. -
Change the script message to language such as:
python print( "Set BROWSERACT_API_KEY securely in the execution environment. " "Do not paste API keys into chat or command-line arguments.", flush=True, ) -
Use the hosting platform's secret manager or protected environment-variable injection mechanism where available.
-
Do not accept the API key as a command-line argument because command lines may be exposed through process listings, shell history, and execution logs.
-
Ensure application logs and error reports never print the
Authorizationheader or environment-variable value. -
Apply least privilege to BrowserAct keys, including account scoping, quota restrictions, expiration, and rotation where supported.
-
Advise users who previously disclosed a key through a conversation to revoke or rotate it and review associated API activity for unauthorized use.
-
