T09 · Insecure Skill Coding Practices
- Location
SKILL.md:26- Finding
API Key Disclosure Through Agent Conversation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:26-29andscripts/youtube_video_api.py:87-90
Vulnerability Type: Unsafe credential handling and potential plaintext secret exposure
Risk Level: MediumVulnerable Code and Instructions
SKILL.md:26-29:markdown Before running, you must check the `BROWSERACT_API_KEY` environment variable. If it is not set, do not take any other actions first. You should request and wait for the user to provide it collaboratively. **The Agent must inform the user at this time**: > "Since you have not configured the BrowserAct API Key yet, please go to the [BrowserAct Console](https://www.browseract.com/reception/integrations) first to get your Key."scripts/youtube_video_api.py:87-90:python print("\n[!] ERROR: BrowserAct API Key is missing.", flush=True) print("Please follow these steps:", flush=True) print("1. Go to: https://www.browseract.com/reception/integrations", flush=True) print("2. Copy your API Key.", flush=True) print("3. Provide it to me or set it as an environment variable (BROWSERACT_API_KEY).", flush=True)Technical Analysis
The Skill explicitly instructs the Agent to request and wait for the user to provide a BrowserAct API key. The script repeats that the key may be provided “to me.” This encourages users to submit a reusable authentication secret through an Agent conversation.
Secrets entered into a conversation may be retained in chat transcripts, telemetry, debugging traces, orchestration logs, or other records accessible to parties who do not require the credential. Conversational submission is unnecessary because the script already supports reading the key from the
BROWSERACT_API_KEYenvironment variable.The script subsequently transmits the key as a Bearer token to the fixed HTTPS endpoint
https://api.browseract.com/v2/workflow. Sending the credential to BrowserAct is consistent with the declared API-backed func ...[truncated 1625 chars]- Remediation
View remediation
Remediation Suggestions
- Remove all instructions asking users to provide API keys directly to the Agent or through chat.
- Require the key to be configured locally through
BROWSERACT_API_KEY, an approved secret manager, or the execution platform's protected secret-injection facility. - Replace the current guidance with an explicit warning such as: “Do not paste the API key into this conversation. Configure it as the
BROWSERACT_API_KEYsecret in your execution environment.” - Change the script message at
scripts/youtube_video_api.py:90so that it only recommends protected environment or secret-manager configuration. - Ensure conversation logs, command output, exceptions, and telemetry never include the credential or the complete
Authorizationheader. - Use a narrowly scoped API key when BrowserAct supports scoped credentials, and apply quota or spending limits where available.
- Rotate any key that has previously been submitted through a conversation or stored in an untrusted log.
- Consider validating that the environment variable is present without printing its value, then pass it only in the HTTPS authorization header as the script currently does.
