T09 · Insecure Skill Coding Practices
- Location
.env:1- Finding
Hardcoded Tavily API Credential
- Content
View full analysis
Vulnerability Details
File Location:
.env:1
Vulnerability Type: Hardcoded secret / plaintext API credential
Risk Level: HighVulnerable Code
dotenv TAVILY_API_KEY=tvly-dev-[REDACTED]The credential is loaded into the process environment and subsequently used to authenticate to Tavily:
python TAVILY_API_KEY = os.environ.get("TAVILY_API_KEY", "")python headers = { 'Authorization': f'Bearer {TAVILY_API_KEY}', 'Content-Type': 'application/json' }Technical Analysis
The project distributes a live-looking Tavily API key in its
.envfile rather than accepting the secret exclusively through secure runtime configuration. Anyone who can download, inspect, clone, archive, or otherwise access the project can recover the credential without bypassing any access control.The three scripts load values from the packaged
.envfile intoos.environ. The search client passes the key toTavilyClient, while the extraction and research clients place it in an HTTP Bearer authorization header. Although these are legitimate uses of the credential, bundling it with the source code breaks secret-separation requirements and makes credential disclosure unavoidable when the project is shared.Attack Path
- An attacker obtains a copy of the project package or repository.
- The attacker opens
.envand extracts the value assigned toTAVILY_API_KEY. - The attacker supplies that value to the Tavily SDK or uses it as a Bearer credential in requests to supported Tavily API endpoints.
- Tavily attributes the requests and associated usage to the exposed credential's account.
- The attacker can continue using the credential until it is revoked, rotated, expired, or otherwise disabled.
Impact Assessment
Successful exploitation does not grant local operating-system privileges, code execution, or persistence. It grants whatever API access and quota are assign ...[truncated 383 chars]
- Remediation
View remediation
Remediation Suggestions
-
Revoke and rotate the exposed Tavily API key immediately; deleting it from the current project does not invalidate copies already obtained.
-
Remove
.envfrom all distributed packages and version-control history. If it was committed, rewrite repository history where practical while treating the credential as permanently compromised. -
Add
.envand other secret-bearing configuration files to.gitignoreand packaging exclusion rules. -
Provide a
.env.examplefile containing only a nonfunctional placeholder such as:dotenv TAVILY_API_KEY=replace-with-your-own-key -
Supply the real credential at runtime through environment injection, a CI/CD secret store, an operating-system credential facility, or a dedicated secrets manager.
-
Apply least privilege, usage limits, billing alerts, and key rotation policies to the replacement credential.
-
Review Tavily usage logs for unauthorized activity associated with the exposed key.
-
Add automated secret scanning to pre-commit hooks and CI pipelines to prevent future credential disclosure.
-
