T09 · Insecure Skill Coding Practices
- Location
scripts/search_workflow.py:12- Finding
Hardcoded Tavily API Credential
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search_workflow.py, line 12
Vulnerability Type: Hardcoded secret
Risk Level: HighVulnerable Code
python TAVILY_API_KEY = os.getenv('TAVILY_API_KEY', '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')The credential is subsequently transmitted in the authorization header:
python def tavily_search(query, max_results=10): """Tavily search""" url = "https://api.tavily.com/search" headers = {"Authorization": f"Bearer {TAVILY_API_KEY}"} data = { "query": query, "search_depth": "advanced", "include_answer": True, "max_results": max_results } response = requests.post(url, json=data, headers=headers, timeout=30) return response.json()Technical Analysis
The application retrieves
TAVILY_API_KEYfrom the environment but supplies a usable-looking API credential as its default value. Consequently, distributing the skill also distributes that credential. Environment-variable support does not protect a secret when source code contains a fallback secret.When the environment variable is absent,
tavily_search()places the embedded credential in a bearer authorization header and sends it to the Tavily API. Any party able to inspect the package can extract the same credential without executing the script or possessing local privileges.Attack Path
- An attacker downloads the published skill or otherwise obtains read access to its source package.
- The attacker opens
scripts/search_workflow.pyand copies the fallback Tavily token from line 12. - The attacker constructs requests to the Tavily API using the token as a bearer credential.
- Tavily accepts requests under the credential owner's account if the exposed token remains active.
- The attacker consumes account quota or performs other operations permitted to that API credential until it is revoked or restricted.
Impact Assessment
Exploitation requires only read ...[truncated 620 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke the exposed Tavily credential immediately and generate a replacement. Treat it as compromised even if no unauthorized use is currently known.
- Review Tavily usage and billing logs for unexpected requests, quota consumption, source addresses, or charges.
- Remove the fallback credential and require explicit secret configuration, for example:
python TAVILY_API_KEY = os.getenv("TAVILY_API_KEY") if not TAVILY_API_KEY: raise RuntimeError("TAVILY_API_KEY must be configured")- Supply the replacement through a secret manager or protected runtime environment variable. Do not place it in source files, documentation, examples, packaged artifacts, or committed configuration.
- If version-control history exists, purge the credential from prior commits and release artifacts. Rotation remains mandatory because history rewriting cannot invalidate previously copied secrets.
- Restrict the replacement credential to the minimum required API permissions and apply provider-supported quotas, spending limits, expiration, and source restrictions where available.
- Add automated secret scanning to pre-commit and CI workflows to prevent future credentials from being committed or published.
- Ensure logs and exception handlers do not print authorization headers or environment-variable values.
