T09 · Insecure Skill Coding Practices
- Location
scripts/lib.py:258- Finding
Huawei Cloud authentication headers are exposed in execution output
- Content
View full analysis
Vulnerability Details
File Location:
scripts/lib.py:258-259,scripts/lib.py:943
Vulnerability Type: Sensitive authentication data disclosure
Risk Level: HighComplete Code Snippet
python print(f"Authorization: {headers.get('Authorization')}") print(f"Request headers: {headers}") print(f"Request body: {body_str}")A second request path also prints all signed headers:
python print(f"Request URL: {url_with_params}") print(f"Request headers: {headers}") resp = requests.request( "GET", url_with_params, headers=headers, verify=True )Technical Analysis
The deployment and UniAgent query paths construct signed Huawei Cloud requests using the supplied access key, secret key, and optional temporary security token. The resulting
headersdictionary can contain anAuthorizationheader with the access-key identifier and request signature. For temporary credentials, it can also contain the rawX-Security-Token.The code prints these headers without redaction. This behavior is reachable during normal deployment and instance-status operations and directly conflicts with the credential-handling requirements in
SKILL.md, which prohibit displaying AK/SK/token data.The dangerous data flow is:
- Credentials are loaded from command-line arguments or
HW_ACCESS_KEY,HW_SECRET_KEY, andHW_SECURITY_TOKEN. - The Huawei signer generates authenticated request headers.
- The complete headers are printed to the process output.
- Skill execution output may be retained in conversation history, terminal logs, CI logs, or agent execution records.
Attack Path
- A user runs the deployment or instance-query command with valid Huawei Cloud credentials.
- The request is signed, including an authorization signature and potentially
X-Security-Token. scripts/lib.pyprints the signed authentication headers.- An unauthorized party with access to execution logs, conversation records, or captured terminal ou ...[truncated 953 chars]
- Credentials are loaded from command-line arguments or
- Remediation
View remediation
Remediation Suggestions
- Remove all output of
Authorization,X-Security-Token, cookies, and complete request-header dictionaries. - Log only non-sensitive metadata, such as:
- HTTP method
- Sanitized host and path
- Generated request ID
- Response status code
- Introduce a centralized redaction function that recursively masks sensitive names, including:
AuthorizationX-Security-TokenCookieandSet-Cookieaccess_key,secret_key, and API-key fields
- Ensure exception messages and SDK diagnostic logging are passed through the same redaction layer.
- Add tests asserting that known credential values never appear in captured stdout or stderr.
- Remove all output of
