T09 · Insecure Skill Coding Practices
- Location
scripts/bj_smoke_v2.py:25- Finding
Hardcoded API Credential Transmitted over Plaintext HTTP
- Content
View full analysis
" ``` ```python def ts(api: str, params: dict, fields: str) -> dict: body = json.dumps({"api_name": api, "token": TUSHARE_TOKEN, "params": params, "fields": fields}) r = urllib.request.Request( "http://api.tushare.pro", data=body.encode(), headers={"Content-Type": "application/json"}, method="POST") return json.loads(urllib.request.urlopen(r, timeout=15).read()) ``` The credential value is redacted from this report to prevent further disclosure. The audited source contains the full token. ### Technical Analysis The script first attempts to obtain `TUSHARE_TOKEN` from the environment but falls back to a complete credential embedded in the source code. Anyone who can read the repository or an installed copy of the Skill can recover and reuse that credential. The `ts()` function then places the token inside a JSON request body and sends it to `http://api.tushare.pro`. Because HTTP does not provide transport encryption, server authentication, or message integrity, the token and requested financial data may be observed or modified by an attacker with access to the network path. The API request itself is consistent with the Skill’s financial-research functionality. However, embedding a shared credential and transmitting it over plaintext HTTP are not necessary for that functionality and violate least-secret-exposure principles. ### Attack Path 1. An attacker obtains read access to the repository, installed Skill directory, source archive, backup, or build log. 2. The attacker extracts the embedded Tushare token and submits API calls under the associated account. 3. Alternativ ...[truncated 999 chars]- Remediation
View remediation
