T09 · Insecure Skill Coding Practices
- Location
scripts/literature_search.py:15- Finding
Hard-Coded Tavily API Credential
- Content
View full analysis
Vulnerability Details
File Location:
scripts/literature_search.py:15
Vulnerability Type: Hard-coded API secret
Risk Level: HighVulnerable Code:
python TAVILY_API_KEY = os.getenv('TAVILY_API_KEY', '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')Technical Analysis
The script embeds a usable-looking Tavily API credential as the default value passed to
os.getenv. IfTAVILY_API_KEYis not configured in the runtime environment, the application automatically authenticates with the credential stored in source code.Secrets embedded in a distributed skill package cannot be kept confidential. Anyone who can download the package, inspect source-control history, access a build artifact, or read an installed copy can recover the credential without executing the script. Environment-variable support does not mitigate this exposure because the hard-coded fallback remains present.
The credential is subsequently placed in a bearer authorization header and sent to Tavily by
tavily_search:python headers = {"Authorization": f"Bearer {TAVILY_API_KEY}"}Attack Path
- An attacker obtains the published skill package or an installed copy.
- The attacker opens
scripts/literature_search.pyand reads line 15. - The attacker extracts the embedded Tavily bearer credential.
- The attacker sends requests directly to the Tavily API using that credential.
- Requests are attributed to the credential owner until the key is revoked, rotated, disabled, or exhausted.
Impact Assessment
Exploitation does not grant local operating-system privileges or code execution on a victim host. It grants unauthorized use of the Tavily API within the permissions assigned to the exposed key.
Potential effects include unauthorized searches, consumption of API quota, possible billing exposure, service disruption through quota exhaustion, and reduced accountability because attacker requests may appear to o ...[truncated 156 chars]
- Remediation
View remediation
Remediation Suggestions
-
Revoke and rotate the exposed Tavily credential immediately; deleting it from the current source file does not invalidate copies already distributed.
-
Remove the hard-coded fallback and require explicit secret provisioning:
python TAVILY_API_KEY = os.getenv("TAVILY_API_KEY") if not TAVILY_API_KEY: raise RuntimeError("TAVILY_API_KEY is required") -
Store the replacement credential in an approved secret manager or protected runtime environment variable, never in source code, documentation, package metadata, examples, or committed configuration files.
-
Review repository history, release archives, build logs, and published artifacts for additional copies. Rewrite history where appropriate, while treating rotation as the primary containment measure.
-
Review Tavily usage and billing records for anomalous activity associated with the exposed key.
-
Apply provider-side restrictions and least-privilege controls where supported, including conservative quotas, spending alerts, expiration, and scoped access.
-
Add automated secret scanning to pre-commit and CI/CD workflows to prevent future credential publication.
-
