T09 · Insecure Skill Coding Practices
- Location
SKILL.md:38- Finding
API Key May Be Transmitted Through a URL Query Parameter
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 38
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: MediumVulnerable Code Snippet
markdown **认证方式**:所有请求必须携带 API Key,通过请求头 `X-API-Key` 传递(也可通过 `?apikey=` 查询参数传递)。**返回格式为纯文本**,非 JSON。The instruction states that the API key may be supplied through the
apikeyURL query parameter, even though header-based authentication is available.Technical Analysis
Secrets transmitted in URL query strings are more likely to be retained outside the intended authentication boundary. The complete URL may be recorded by gateway and reverse-proxy access logs, observability platforms, request traces, shell history, debugging output, and intermediary infrastructure.
This behavior is not required for the Skill's declared functionality because the same API supports the
X-API-Keyheader, which the remainder of the Skill already uses. Permitting query-string authentication therefore exceeds the minimum credential exposure necessary to execute metric searches and queries.No hardcoded key was found. The Skill otherwise reads only the dedicated
CAN_API_KEYenvironment variable and restricts declared outbound access togateway.can.aloudata.com.Attack Path
- An agent or user follows the documented
?apikey=authentication option. - The shell expands or otherwise inserts the
CAN_API_KEYvalue into the request URL. - The complete URL is retained in local command history, gateway logs, proxy logs, monitoring telemetry, or request traces.
- A party with access to one of those records extracts the API key.
- The exposed key is replayed against
gateway.can.aloudata.com. - The attacker performs metric searches, dimension discovery, or authenticated metric queries within the permissions granted to the compromised key.
Impact Assessment
Successful exploitation grants the attacker the same gateway privileges as the exposed API key. Depending on the ...[truncated 425 chars]
- An agent or user follows the documented
- Remediation
View remediation
Remediation Suggestions
- Remove the documented
?apikey=authentication option. - Require authentication exclusively through the
X-API-Keyrequest header. - Preserve the existing environment-variable approach and never place the expanded key directly in a command-line URL.
- Ensure diagnostic output, traces, and error reports redact
X-API-Keyvalues. - Avoid displaying commands after shell expansion or enabling execution tracing while authenticated requests run.
- Configure the gateway and intermediary infrastructure to reject query-string API keys.
- Review available access, proxy, and observability logs for previously recorded
apikeyparameters; redact or delete affected records according to retention policy. - Rotate any key that may previously have been transmitted in a URL.
- Apply least-privilege server-side scopes, expiration, and rotation policies to
CAN_API_KEY.
- Remove the documented
