T09 · Insecure Skill Coding Practices
- Location
wechatai.py:414- Finding
API Credentials Are Exposed Through Interactive Input and Console Logging
- Content
View full analysis
&1 | tee debug.log ``` Under that documented workflow, the disclosed credentials can be persisted in a plaintext file. ### Attack Path 1. The user starts the Skill without setting `QWEN_API_KEY`. 2. The program prompts for Qwen and Baidu credentials. 3. The user enters the secrets, which are displayed because `input()` does not mask them. 4. The program prints all credentials in full at line 427. 5. Terminal output is retained ...[truncated 831 chars]- Remediation
View remediation
