T09 · Insecure Skill Coding Practices
- Location
scripts/run_mystery.py:85- Finding
Untrusted Environment Configuration Can Redirect Credentials and Sensitive Content
- Content
View full analysis
None: if load_dotenv is None: return for path in (SKILL_DIR / ".env", Path.cwd() / ".env"): if path.exists(): load_dotenv(path) ``` ```python LLM_BASE_URL = os.environ.get( "MYSTERY_LLM_BASE_URL", "https://models.audiozen.cn/v1", ) LLM_API_KEY = os.environ.get( "MYSTERY_LLM_API_KEY", os.environ.get("IME_MODEL_API_KEY", ""), ) ASR_URL = os.environ.get( "MYSTERY_ASR_URL", "https://api.senseaudio.cn/v1/audio/transcriptions", ) ASR_API_KEY = os.environ.get("SENSEAUDIO_API_KEY", "") TTS_URL = os.environ.get( "MYSTERY_TTS_URL", "https://api.senseaudio.cn/v1/t2a_v2", ) TTS_API_KEY = os.environ.get("SENSEAUDIO_API_KEY", "") ``` ```python def build_client() -> OpenAI: api_key = require_env( "MYSTERY_LLM_API_KEY / IME_MODEL_API_KEY", LLM_API_KEY, ) return OpenAI( api_key=api_key, base_url=LLM_BASE_URL, timeout=LLM_TIMEOUT, ) ``` ```python headers = { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json", } response = requests.post( TTS_URL, headers=headers, json=payload, timeout=TTS_TIMEOUT, ) ``` ```python headers = {"Authorization": f"Bearer {api_key}"} data = {"model": ASR_MODEL, "response_format": "verbose_json"} with audio_path.open("rb") as handle: files = {"file": (audio_path.name, handle)} response = requests.post( ASR_URL, headers=headers, data=data, files=files, timeout=ASR_TIMEOUT, ) ``` ### Technical Analysis The Skill legitimately requires network access for LLM generation, speech recognition, and speech synthesis. However, it automatically loads configuration f ...[truncated 2943 chars]- Remediation
View remediation
