T09 · Insecure Skill Coding Practices
- Location
scripts/tc001.py:36- Finding
Plaintext Transmission of YouTube API Key and Device Configuration
- Content
View full analysis
Vulnerability Details
File Location:
scripts/tc001.py:36-37,scripts/tc001.py:73-78,scripts/tc001.py:88-97,scripts/tc001.py:138-148,scripts/tc001.py:157-163,scripts/tc001.py:314-361
Vulnerability Type: Sensitive information transmitted over unencrypted HTTP
Risk Level: HighThe device endpoint is constructed using HTTP rather than HTTPS:
python HOST = load_host() BASE = f"http://{HOST}"The application settings include a YouTube API key:
python APP_TEXT_FIELDS = [ "cityCode", "bilibiliUid", "bilibiliAnimation", "bilibiliColor", "bilibiliFormat", "weiboUid", "weiboAnimation", "weiboColor", "weiboFormat", "youtubeUid", "youtubeApikey", "youtubeAnimation", "youtubeColor", "youtubeFormat", "douyinUid", "douyinAnimation", "douyinColor", "douyinFormat", "awtrixServer", "awtrixPort", ]All supplied settings are form-encoded and sent to the configured HTTP destination:
python def http_post(path: str, data: dict) -> str: body = urlencode(data).encode("utf-8") req = Request(BASE + path, data=body, method="POST") req.add_header("Content-Type", "application/x-www-form-urlencoded") with urlopen(req, timeout=5) as r: return r.read().decode("utf-8", errors="ignore")Existing application settings, including the API key, are read into a dictionary and submitted again when settings are saved:
python def load_app_settings(): html = http_get("/app_switch") data = {} for name, field in GADGET_FIELDS.items(): data[field] = "on" if _checkbox_checked(html, field) else "" for f in APP_TEXT_FIELDS: data[f] = _input_value(html, f) return data def save_app_settings(data: dict): payload = {"page": "app_switch"} payload.update(data) return http_post("/app_switch", payload)For example, changing a single gadget causes the complete application ...[truncated 2768 chars]
- Remediation
View remediation
Remediation Suggestions
- Use authenticated HTTPS for device communication if supported by the device firmware.
- If the device only supports HTTP, clearly warn users that credentials must not be configured or transmitted over an untrusted network.
- Avoid resending
youtubeApikeyduring unrelated updates. Prefer a dedicated API operation that sends only the field being changed. - If the device requires complete form submissions, provide an explicit confirmation before retransmitting sensitive fields and document the network exposure.
- Validate the configured host. By default, restrict it to private or loopback addresses and require explicit opt-in for public destinations.
- Protect configuration files containing host or credential-related information with restrictive filesystem permissions.
- Never print sensitive values in command output, exceptions, or debug logs.
- Where supported by the external service, restrict the YouTube API key by API, quota, source, and billing controls, and rotate any key suspected of interception.
