T09 · Insecure Skill Coding Practices
- Location
search.js:17- Finding
Hard-Coded Huawei Cloud Bearer Token in Distributed Source Code
- Content
View full analysis
Vulnerability Details
File Location:
search.js:17-18
Vulnerability Type: Hard-coded cloud API credential
Risk Level: Highjavascript // Huawei Cloud API Token (obtained from SKILL.md) const TOKEN = 'eyJhbGciOiJQUzI1NiIsImtpZCI6IjNjMWZhNWQwNjIxNzRkYTA4MWNlY2E4NTY3NDViYTQxIiwidHlwIjoiSldUIn0.[REDACTED EXPOSED JWT]';The original file contains the complete bearer token. Its payload and signature are redacted in this report to avoid further disclosure.
The credential is subsequently attached to every API request at
search.js:39-42:javascript headers: { 'Content-Type': 'application/json', 'Authorization': `Bearer ${TOKEN}` },Technical Analysis
The project embeds an authentication bearer token directly in distributable source code. Bearer tokens authorize their holder without requiring additional proof of identity, so anyone who can download the package, access its source, inspect an installed copy, or read a repository containing it can extract and reuse the credential.
This is an intentional implementation choice rather than an accidental debug artifact:
SKILL.mdstates that the token is built into the code, while_meta.jsondeclares no environment-based secret configuration. Source-level embedding prevents effective per-installation access control and makes credential rotation require a code or package update.The token appears structurally consistent with a signed JWT and therefore must be treated as compromised regardless of whether it is currently active. No attempt to use the exposed credential was made during this static audit.
Attack Path
- An attacker downloads the Skill package or reads an installed copy of
search.js. - The attacker copies the JWT assigned to
TOKEN. - The attacker sends requests to the declared Huawei Cloud endpoint:
https://connect-api.cloud.huawei.com/api/aiNetworking/v1/webSearch. - The attacker supplies the copied ...[truncated 1007 chars]
- An attacker downloads the Skill package or reads an installed copy of
- Remediation
View remediation
Remediation Suggestions
-
Revoke the exposed token immediately and issue a replacement; assume the committed value has already been compromised.
-
Remove the token from source code, documentation, package artifacts, repository history, release archives, logs, and examples.
-
Read the credential from an environment variable or secret manager, for example:
javascript const TOKEN = process.env.HUAWEI_WEB_SEARCH_TOKEN; if (!TOKEN) { throw new Error('HUAWEI_WEB_SEARCH_TOKEN is required'); } -
Declare only the required environment variable in the Skill metadata rather than supplying a default credential.
-
Provision a separate credential per deployment and grant only the minimum API scope needed for web search.
-
Prefer short-lived credentials and automated rotation over long-lived static bearer tokens.
-
Add secret scanning to development and release pipelines, including JWT and cloud-token detection.
-
Review Huawei Cloud access logs for unauthorized use of the exposed token and investigate unexpected requests, quota use, or source addresses.
-
Ensure errors and diagnostic output never print authorization headers or token values.
-
