T09 · Insecure Skill Coding Practices
- Location
SKILL.md:27- Finding
API Key Disclosure Through Agent Conversation
- Content
View full analysis
"Since you have not configured the BrowserAct API Key, please go to the [BrowserAct Console](https://www.browseract.com/reception/integrations) first to get your Key." ``` `scripts/youtube_search_api.py:86-90`: ```python if not api_key: print("\n[!] ERROR: BrowserAct API Key is missing.", flush=True) print("Please follow these steps:", flush=True) print("1. Go to: https://www.browseract.com/reception/integrations", flush=True) print("2. Copy your API Key.", flush=True) print("3. Provide it to me or set it as an environment variable (BROWSERACT_API_KEY).", flush=True) ``` ### Technical Analysis The Skill directs the Agent to request the user's collaboration in providing an API key, while the script explicitly tells the user to “Provide it to me.” This can encourage the user to paste a long-lived BrowserAct credential into an Agent conversation. A credential entered into a conversation may be retained in chat history, model traces, platform telemetry, debugging records, or other logs. This exposure is unnecessary because the implementation already supports reading the key from the `BROWSERACT_API_KEY` environment variable. The script does not print the key after reading it, and its transmission as an HTTPS Bearer token to the declared BrowserAct API is necessary for the stated functionality. The vulnerability is therefore in the credential-provisioning guidance, not in the authenticated API request itself. ### Attac ...[truncated 1099 chars]- Remediation
View remediation
