T09 · Insecure Skill Coding Practices
- Location
analyze_stock.py:93- Finding
Hardcoded Finnhub API Credential Exposed Across Source Files
- Content
View full analysis
Vulnerability Details
File Location:
analyze_stock.py:93-101
Additional Locations:company_info.py:3-6,jd_logistics.py:4-7,report_v2.py:114-120,stock_analyst.py:39,stock_analyst.py:109-110,test_stock.py:5-9
Vulnerability Type: Hardcoded API credential and credential disclosure through URL query parameters
Risk Level: MediumVulnerable Code
python def get_us_stock(code): """获取美股行情""" FINNHUB_KEY = 'd6nucg1r01qse5qn5e90d6nucg1r01qse5qn5e9g' code = code.strip().upper() url = f'https://finnhub.io/api/v1/quote?symbol={code}&token={FINNHUB_KEY}' try: r = requests.get(url, timeout=10).json()The same credential is also embedded in other files. For example:
python token = 'd6nucg1r01qse5qn5e90d6nucg1r01qse5qn5e9g' company = requests.get( f'https://finnhub.io/api/v1/stock/profile2?symbol=JD&token={token}' ).json()python FINNHUB_KEY = os.environ.get( 'FINNHUB_API_KEY', 'd6nucg1r01qse5qn5e90d6nucg1r01qse5qn5e9g' )Technical Analysis
A reusable Finnhub API token is committed directly to multiple project files. The environment-variable implementation in
stock_analyst.pydoes not resolve the exposure because it falls back to the same public credential wheneverFINNHUB_API_KEYis absent.The credential is also placed in URL query strings. Query strings may be retained by HTTP client diagnostics, reverse proxies, monitoring systems, browser history, or upstream service logs. Although HTTPS protects the request in transit, it does not prevent disclosure through source distribution or URL logging.
Anyone with access to the repository or distributed Skill package can recover and reuse the credential without authentication to the host system.
Attack Path
- An attacker downloads, clones, or otherwise obtains the project.
- The attacker searches the source tree for ...[truncated 858 chars]
- Remediation
View remediation
Remediation Suggestions
-
Immediately revoke and rotate the exposed Finnhub token.
-
Remove every hardcoded copy from:
analyze_stock.pycompany_info.pyjd_logistics.pyreport_v2.pystock_analyst.pytest_stock.py
-
Require the credential through a runtime secret source and fail closed when it is missing:
python import os FINNHUB_KEY = os.environ.get("FINNHUB_API_KEY") if not FINNHUB_KEY: raise RuntimeError("FINNHUB_API_KEY is required") -
Do not retain a default or demonstration credential in production code.
-
Use an authorization header rather than a query parameter if the service supports it. If Finnhub requires a query parameter, prevent full request URLs from being written to application, proxy, or diagnostic logs.
-
Add
.envand local secret files to.gitignore; provide a.env.examplecontaining only placeholder values. -
Enable automated secret scanning in version control and CI.
-
Review repository history and published artifacts because deleting the token from the latest revision does not remove it from earlier commits or forks.
-
Apply provider-side rate limits, usage alerts, and any available token restrictions.
-
