T09 · Insecure Skill Coding Practices
- Location
utils.py:19- Finding
API Secret Disclosed Through Standard Output
- Content
View full analysis
Vulnerability Details
File Location:
utils.py:19-34
Vulnerability Type: Sensitive credential exposure through logging
Risk Level: HighVulnerable Code
python def jiuma_request(url, data={}): try: response = requests.post(url, data, timeout=30) if response.status_code != 200: output_result({ "status": "error", "message": f"请求远程API失败,状态码: {response.status_code}", "data": {} }) return None json_result = response.json() if json_result.get("code") != 200: output_result({ "status": "error", "message": f"API返回错误: {json_result.get('message', '未知错误')}", "data": json_result }) return print(json_result) return json_result.get("data")The affected helper is used by the login-status workflow:
python def check_login_status(access_token): data = jiuma_request(f"{CHECK_API}?rand_string={access_token}") if not data: return save_jiuma_api_key(data["secret_key"])Technical Analysis
jiuma_request()prints the complete successful API response before returning itsdatafield. The login-status endpoint returns asecret_key, whichcheck_login_status()subsequently saves as the user's API key. Therefore, the complete response containing that credential can be written to standard output.Standard output is not a protected secret-storage channel. In an agent or automation environment, it may be captured in tool transcripts, conversation history, CI logs, terminal recordings, monitoring systems, or centralized log storage. This expands access to the API key beyond the process that legitimately needs it.
Attack Path
- A user completes the QR-code login flow.
- The user invokes
login.py --checkwith a valid login t ...[truncated 945 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
print(json_result)from the shared request helper. - Return parsed results internally without logging complete response objects.
- Use an allowlist when operational output is necessary, such as status code and a non-sensitive message.
- Implement recursive redaction for fields including
secret_key,api_key,access_token,rand_string,authorization, and similar credential names. - Ensure error handling does not include complete server response bodies where credentials might also be present.
- Review and purge retained agent, terminal, and CI logs that may already contain exposed keys.
- Rotate API keys that may have passed through the vulnerable login flow.
- Remove
