T09 · Insecure Skill Coding Practices
- Location
index.js:6- Finding
Hard-Coded Payment Merchant Credential
- Content
View full analysis
Vulnerability Details
File Location:
index.js:6-9and credential use atindex.js:48-55
Vulnerability Type: Hard-coded secret in distributed source code
Risk Level: HighVulnerable Code
javascript const CONFIG = { skillpay_api: 'https://api.skillpay.me/v1', merchant_key: process.env.SKILLPAY_MERCHANT_KEY || 'sk_91fff75ae2a7a71f8eceadcbcd816e24d57e58d9d04ccca45f0b3856af130aea', price_per_use: 0.001, currency: 'USDT' };The credential is subsequently sent to the payment service:
javascript const response = await axios.post(`${CONFIG.skillpay_api}/billing/charge`, { amount: CONFIG.price_per_use, currency: CONFIG.currency, merchant_key: CONFIG.merchant_key, description: 'Email subject generation by Sloan' }, { headers: { 'Content-Type': 'application/json' }, timeout: 10000 });Technical Analysis
A live-looking SkillPay merchant key is embedded directly in the distributed JavaScript source. Environment-variable support does not protect the default credential because every person who downloads the package can read and reuse the fallback value.
The key is supplied as an authentication or merchant-identification value in payment requests. Consequently, its effective permissions depend on the server-side authorization implemented by
api.skillpay.me. The available code does not establish that the key grants account administration or fund withdrawal privileges, but it does establish that the package distributes the value used when submitting billing operations.Public documentation also advertises the embedded key as the default, so the exposure is intentional from a functional perspective but remains an insecure credential-management practice.
Attack Path
- An attacker downloads the public skill package or reads
index.js. - The attacker extracts the
sk_...merchant credential. - The attacker creates independent requests to the SkillPay b ...[truncated 846 chars]
- An attacker downloads the public skill package or reads
- Remediation
View remediation
Remediation Suggestions
- Immediately revoke and rotate the exposed merchant key.
- Remove the fallback credential from the source code and repository history.
- Require
SKILLPAY_MERCHANT_KEYto be supplied through a protected environment variable or operating-system credential store, and fail safely when it is absent. - Do not distribute a shared merchant secret to clients. Prefer a server-mediated payment design in which an authenticated backend retains the credential and creates narrowly scoped, short-lived payment authorizations.
- Ensure the payment server determines the merchant identity from authenticated credentials rather than trusting a client-controlled request-body field.
- Apply least-privilege scopes, transaction limits, replay protection, rate limiting, request signing, and anomaly monitoring.
- Add secret scanning to source-control and release pipelines to prevent future credential publication.
