T09 · Insecure Skill Coding Practices
- Location
SKILL.md:76- Finding
API Credential Exposed Through URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 76-84
Vulnerability Type: API credential exposure through URL query parameters
Risk Level: Mediumpython params = { 'series_id': series_id, 'observation_start': start_date, 'observation_end': end_date, 'file_type': 'json' } if self.fred_api_key: params['api_key'] = self.fred_api_key try: response = requests.get(self.FRED_BASE, params=params)Technical Analysis
The optional FRED API key is added to the
paramsdictionary passed torequests.get. The Requests library serializes these parameters into the request URL. Although the request uses HTTPS and is sent to the declared official FRED API endpoint, URL query strings can be recorded by HTTP client diagnostics, reverse proxies, monitoring systems, server access logs, browser-like debugging tools, and exception telemetry.This behavior is directly related to the Skill's declared price-fetching functionality and is not evidence of covert exfiltration. However, transmitting credentials in URLs expands their potential exposure compared with authorization headers. If the FRED API requires query-string authentication, the residual risk should be documented and URL logging must be controlled.
Attack Path
- A user supplies a valid FRED API key when initializing
OpenPriceAPI. - The Skill places the credential in the
api_keyquery parameter. requests.getserializes the key into the complete request URL.- A proxy, server, diagnostic facility, or telemetry system records the URL.
- An attacker or unauthorized operator with access to those logs recovers the API key.
- The exposed key is used to make unauthorized FRED API requests under the user's account or quota.
Impact Assessment
Successful exploitation could disclose the supplied FRED API credential. The resulting access is limited to the permissions and quota associated with that ...[truncated 304 chars]
- A user supplies a valid FRED API key when initializing
- Remediation
View remediation
Remediation Suggestions
- Prefer an API-supported authorization header rather than a query parameter, if the FRED API supports such an authentication method.
- If the API mandates query-string authentication, explicitly document that the credential is transmitted to FRED in the URL.
- Disable verbose HTTP tracing in production and ensure application, proxy, monitoring, and exception logs redact the
api_keyparameter. - Never include the final request URL or request parameters in user-visible errors.
- Retrieve the key from a protected secret store or environment variable rather than embedding it in source code or notebooks.
- Use a dedicated key with the minimum available privileges and quota, rotate it periodically, and revoke it immediately if log exposure is suspected.
- Where practical, isolate the FRED request behind a narrowly scoped client that enforces the expected hostname and credential-redaction policy.
