T09 · Insecure Skill Coding Practices
- Location
simple_stock.py:71- Finding
Hard-Coded Finnhub API Credential
- Content
View full analysis
Vulnerability Details
File Location:
simple_stock.py:71-72
Vulnerability Type: Hard-coded API credential
Risk Level: MediumVulnerable Code
python FINNHUB_KEY = 'd6nucg1r01qse5qn5e90d6nucg1r01qse5qn5e9g' url = f'https://finnhub.io/api/v1/quote?symbol={code.upper()}&token={FINNHUB_KEY}'Technical Analysis
A reusable Finnhub API token is embedded directly in the distributed source code. Any user who can access the project can retrieve this credential without authentication. The token is also placed in the URL query string, which may expose it through application logs, HTTP client diagnostics, monitoring systems, proxy logs, or request histories.
Although the request uses HTTPS and therefore protects the URL in transit from passive network observers, HTTPS does not prevent disclosure through source distribution or endpoint-side logging.
Attack Path
- An attacker downloads or otherwise obtains access to the Skill package.
- The attacker opens
simple_stock.pyand extracts the value assigned toFINNHUB_KEY. - The attacker submits arbitrary requests to the Finnhub API using the exposed token.
- The requests consume the token owner's API quota and may cause throttling or service interruption for legitimate users.
- If the associated Finnhub account has paid usage or additional API permissions, the attacker may also create billing exposure or access any data authorized to that token.
Impact Assessment
Exploitation does not grant local system privileges or code-execution capabilities. Its scope is limited to the Finnhub account and API permissions associated with the exposed token. Potential consequences include unauthorized API use, quota exhaustion, rate limiting, loss of service availability, and possible billing impact. The exact account-level impact depends on the privileges and subscription attached to the token.
- Remediation
View remediation
Remediation Suggestions
- Immediately revoke and rotate the exposed Finnhub token.
- Remove the credential from source code and repository history.
- Read the token from an environment variable or protected secret store, for example:
python import os finnhub_key = os.environ.get("FINNHUB_API_KEY") if not finnhub_key: raise RuntimeError("FINNHUB_API_KEY is not configured") - Prevent secret files such as
.envfrom being committed through.gitignoreand repository secret-scanning controls. - Use an authorization header instead of a query parameter if supported by the service. If the API requires a query parameter, ensure HTTP diagnostics and proxy logs redact it.
- Apply token restrictions, usage limits, and billing alerts where Finnhub supports them.
- Add automated secret scanning to the development and release process.
