T09 · Insecure Skill Coding Practices
- Location
webhook-functions.ps1:184- Finding
Webhook Credentials Are Exposed Through Console and Batch Output
- Content
View full analysis
Vulnerability Details
File Location:
webhook-functions.ps1:184-190andwebhook-functions.ps1:209-211
Vulnerability Type: Sensitive information exposure through application output
Risk Level: MediumVulnerable Code
powershell $results += @{ Url = $url Platform = Get-WebhookPlatform -Url $url Success = $result Timestamp = Get-Date -Format "yyyy-MM-dd HH:mm:ss" }powershell Write-Host "🧪 测试 $platform Webhook..." -ForegroundColor Cyan Write-Host "URL: $Url" Write-Host "消息:$testMsg"The documentation also explicitly demonstrates displaying the returned URL field:
File Location:
SKILL.md:159-160powershell $results = Send-Webhook-Batch -Urls $urls -Message "广播" $results | Format-Table Url, Success, TimestampTechnical Analysis
Webhook URLs are generally bearer credentials rather than ordinary public endpoints. Depending on the provider, reusable secrets appear in query parameters such as
access_tokenorkey, or in path components such as Slack, Discord, Feishu, and Telegram tokens.Send-Webhook-Batchreturns the complete caller-supplied URL in every result object.Test-Webhook-Connectionprints the complete URL directly to the console. The documented batch workflow then encourages users to display that field.Console output and returned objects may be retained in CI logs, shell transcripts, monitoring systems, support bundles, or AI-agent conversation records. No masking or redaction is applied to sensitive query parameters or path segments.
Attack Path
- A user configures a valid webhook URL containing an access token, key, or bot secret.
- The user invokes
Test-Webhook-ConnectionorSend-Webhook-Batch. - The complete credential-bearing URL is printed or returned in a result object.
- A CI system, terminal logger, monitoring service, or agent transcript retains the output.
- A party with access to th ...[truncated 673 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not print or return complete webhook URLs. Return only the platform, delivery status, timestamp, and a non-sensitive endpoint identifier.
- Introduce a dedicated redaction function that:
- Removes values for query parameters such as
access_token,key,token, andsecret. - Masks provider-specific secret path components.
- Preserves only enough information for troubleshooting, such as the hostname and final four characters of an identifier.
- Removes values for query parameters such as
- Replace
Write-Host "URL: $Url"with output such asWrite-Host "Platform: $platform"or a safely redacted URI. - Ensure exception and verbose logging also pass URLs through the same redaction function.
- Change batch result objects from
Url = $urlto a field such asEndpoint = Protect-WebhookUrl $url. - Update documentation so examples never recommend displaying raw webhook URLs.
- Rotate any production webhook credentials that may already have appeared in persistent logs.
