T09 · Insecure Skill Coding Practices
- Location
scripts/scholar-search.mjs:68- Finding
SearchAPI Credential Disclosed to the SerpApi Endpoint in Scholar Search
- Content
View full analysis
Vulnerability Details
File Location:
scripts/scholar-search.mjs, lines 68 and 238-248
Vulnerability Type: Cross-provider API credential disclosure
Risk Level: HighVulnerable Code
js const apiKey = (process.env.SERPAPI_API_KEY || process.env.SEARCHAPI_API_KEY || '').trim();js const u = new URL('https://serpapi.com/search.json'); u.searchParams.set('engine', 'google_scholar'); u.searchParams.set('q', query); u.searchParams.set('num', String(n)); u.searchParams.set('api_key', apiKey); u.searchParams.set('hl', lang || 'en'); if (yearFrom) u.searchParams.set('as_ylo', yearFrom); if (yearTo) u.searchParams.set('as_yhi', yearTo); let data; try { data = await fetchJson(u, { headers: { 'Accept': 'application/json' } });Technical Analysis
The script treats
SERPAPI_API_KEYandSEARCHAPI_API_KEYas interchangeable credentials, but the request destination is unconditionally fixed tohttps://serpapi.com/search.json. If onlySEARCHAPI_API_KEYis configured, its value is therefore sent to SerpApi rather than to the provider for which it was provisioned.The credential is also placed in the URL query string. Although HTTPS protects the request in transit, the complete URL is visible to the destination service and may be retained in server access logs, reverse-proxy logs, monitoring systems, or diagnostic records.
Sending a search query and a valid credential to the selected search provider is necessary for the declared Scholar search functionality. Sending a credential associated with a different provider is not necessary and violates least-privilege and credential-boundary principles.
Attack Path
- A user follows the Skill documentation and configures
SEARCHAPI_API_KEY. SERPAPI_API_KEYis absent, causing the script to selectSEARCHAPI_API_KEY.- The user invokes
scholar-search.mjswith an academic search query. - The script inserts the select ...[truncated 1092 chars]
- A user follows the Skill documentation and configures
- Remediation
View remediation
Remediation Suggestions
- Bind every accepted credential variable to its corresponding provider endpoint. Use
SERPAPI_API_KEYonly withserpapi.com. - If the public edition supports only SerpApi, remove the
SEARCHAPI_API_KEYfallback and reject configurations that do not provideSERPAPI_API_KEY. - If both providers must be supported, select an allowlisted endpoint according to the configured credential and implement provider-specific request parameters.
- Reject ambiguous configurations rather than silently routing one provider's credential to another provider.
- Prefer an authorization header over a URL parameter when the provider supports it. If a query parameter is mandatory, ensure URLs containing credentials are redacted from errors, telemetry, and application logs.
- Update
SKILL.mdand metadata so the documented environment requirements exactly match runtime behavior. - Add automated tests asserting that
SEARCHAPI_API_KEYcan never be transmitted toserpapi.com, and that each supported credential can reach only an explicitly allowlisted hostname. - Rotate any
SEARCHAPI_API_KEYpreviously used with this implementation if disclosure is considered possible.
- Bind every accepted credential variable to its corresponding provider endpoint. Use
