T09 · Insecure Skill Coding Practices
- Location
main.py:7- Finding
Hard-Coded Tushare API Token
- Content
View full analysis
Vulnerability Details
File Location:
main.py, line 7
Vulnerability Type: Hard-coded API credential
Risk Level: HighVulnerable Code
python ts.set_token("885cd28a17a52b35e5da6abb8ac11e20e85483affa4c4de8a9e6a928")Technical Analysis
A reusable Tushare API token is embedded directly in the source code. Anyone who can read the project files, source repository, distributed package, build artifacts, or logs containing this code can recover the credential without authentication.
Because the token is passed to
ts.set_token, it is used as the credential for subsequent Tushare API requests. An attacker can copy it into an independent Tushare client and make requests outside the intended skill. The source also lacks a secure runtime secret-loading mechanism.Attack Path
- Obtain read access to the project, repository, package, or another artifact containing
main.py. - Read line 7 and extract the embedded token.
- Configure a separate Tushare client with the exposed token.
- Submit API requests under the token owner's identity until the token is revoked or restricted.
- Consume available quota or access any Tushare operations and data authorized for that credential.
Impact Assessment
Exploitation grants the attacker the API privileges associated with the exposed Tushare token; it does not, based on the audited code, directly grant host operating-system privileges. Potential consequences include unauthorized API usage, account or quota abuse, service disruption through quota exhaustion, and access to API functionality available to the token owner. The exact scope depends on the token's server-side permissions and account plan.
- Obtain read access to the project, repository, package, or another artifact containing
- Remediation
View remediation
Remediation Suggestions
-
Revoke and rotate the exposed token immediately; removing it from the current source alone does not invalidate copies.
-
Remove the token from source code and repository history, including prior commits, release archives, caches, and build artifacts where feasible.
-
Load the token at runtime from a protected environment variable or secret-management service, for example:
python import os import tushare as ts token = os.environ.get("TUSHARE_TOKEN") if not token: raise RuntimeError("TUSHARE_TOKEN is not configured") ts.set_token(token) -
Ensure secret values are never included in logs, exceptions, return data, documentation, or test fixtures.
-
Apply least-privilege restrictions and usage limits to the replacement credential where supported.
-
Add secret scanning to version-control and CI workflows to prevent future credential commits.
-
Document the external Tushare dependency and secure credential configuration requirement in
SKILL.mdwithout including a real token.
-
