T09 · Insecure Skill Coding Practices
- Location
doubao_video_creator.py:27- Finding
Multiple Hardcoded Service Credentials Exposed in Source and Documentation
- Content
View full analysis
Vulnerability Details
File Locations:
doubao_video_creator.py:27-28element_generator.py:19-20SKILL.md:101-102SKILL.md:166-177project_template.json:19-21CLAWHUB_PUBLISH_LOG.md:10FINAL_PUBLISH_GUIDE.md:33quick_push_github.sh:27-37quick_push_github.sh:46-48
Vulnerability Type: Hardcoded API keys and access tokens
Risk Level: HighEvidence
doubao_video_creator.py:27-28:python # Default API key DEFAULT_API_KEY = "65ae8f92-134c-4194-a3af-6e6cb74284e0"element_generator.py:19-20:python # Configuration API_KEY = "sk-d05aba5a2dae4453b97ed07fdb983e5a"SKILL.md:101-102:markdown **API Key**: `65ae8f92-134c-4194-a3af-6e6cb74284e0` **API Endpoint**: `https://ark.cn-beijing.volces.com/api/v3/contents/generations/tasks`quick_push_github.sh:27-37:bash echo "💡 提示:首次推送需要输入 GitHub 凭证" echo " 用户名:465367@qq.com" echo " 密码/令牌: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" echo "" # 使用 GIT_ASKPASS 自动提供凭证 export GIT_ASKPASS=/bin/echo export GIT_USERNAME="465367@qq.com" export GIT_PASSWORD="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"Technical Analysis
The project contains credential-shaped values for Volcengine, an image-generation service, GitHub, and ClawHub. These values are embedded in executable source, templates, documentation, logs, and shell scripts.
Secrets committed to a distributed package must be treated as compromised because every package recipient can extract them. Removing the current files does not remove the values from existing copies or version-control history. The GitHub token is additionally exported into the process environment and printed to the terminal, potentially exposing it through logs, captured terminal output, or process-inspection mechanisms available to the same user.
The credentials were not validated against their corresponding services during this s ...[truncated 1123 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke and rotate every exposed credential immediately.
- Purge the values from Git history using an appropriate history-rewriting tool, then coordinate replacement clones with all contributors.
- Remove credentials from source files, documentation, templates, examples, logs, and shell scripts.
- Obtain credentials at runtime from an OS keyring, secret manager, or protected environment variable.
- Do not provide a functional default credential. Fail closed when no user-supplied credential is available.
- Add automated secret scanning to pre-commit and CI workflows.
- Restrict replacement credentials to the smallest possible service scopes, quotas, and expiration periods.
- Ensure logs and error messages redact authorization headers and token values.
