T09 · Insecure Skill Coding Practices
- Location
scripts/agnes_gen.py:39- Finding
Hardcoded Agnes API Credential Exposed in Executable Code and Documentation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/agnes_gen.py:36-39, 139-145;SKILL.md:97, 119, 208, 223, 241, 260, 284
Vulnerability Type: Hardcoded secret and insecure credential fallback
Risk Level: HighThe project embeds a live-looking Agnes bearer token in executable code and repeatedly exposes it in command examples.
python # Built-in default key (fallback) DEFAULT_API_KEY = "sk-8Rzd2yCbFzOi1vxojseH8C5D8w3u4aMdNWsPNzxk0G7339Cz"The credential is automatically selected when the caller does not provide another key:
python def get_api_key(user_key=None): """Priority: user-provided, environment variable, built-in default.""" if user_key: return user_key env_key = os.environ.get("AGNES_API_KEY", "").strip() if env_key: return env_key return DEFAULT_API_KEYThe documentation also exposes the bearer token in directly executable examples:
bash curl -s -X POST "https://apihub.agnes-ai.com/v1/images/generations" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer sk-8Rzd2yCbFzOi1vxojseH8C5D8w3u4aMdNWsPNzxk0G7339Cz" \ -d '{ "model": "agnes-image-2.1-flash", "prompt": "<user image description>", "size": "2K", "ratio": "1:1", "extra_body": { "response_format": "url" } }'Technical Analysis
API bearer tokens must be treated as secrets and supplied through a protected runtime secret mechanism. Embedding one in a distributable Skill grants every package recipient access to the credential. It can also persist in source-control history, build artifacts, logs, caches, forks, and copied documentation after removal from the current version.
The fallback behavior makes the exposure operational rather than illustrative: unless
--keyorAGNES_API_KEYis set, the script transmits the embedded credential in theAuthorizationheader to a configured Agnes endpoint ...[truncated 2053 chars]- Remediation
View remediation
Remediation Suggestions
- Immediately revoke and rotate the exposed credential. Treat it as compromised even if usage logs currently appear normal.
- Remove
DEFAULT_API_KEYand eliminate the built-in fallback. Fail closed with a clear error when no credential is securely supplied. - Obtain the key only through a protected runtime mechanism, such as
AGNES_API_KEY, an operating-system credential store, or the deployment platform's secret manager. - Replace every credential in
SKILL.mdwith a nonfunctional placeholder such asYOUR_API_KEY. - Remove the secret from repository history, release archives, caches, generated artifacts, and previously published Skill packages where feasible.
- Inspect Agnes API usage and authentication logs for unauthorized activity associated with the exposed key.
- Apply the narrowest available API scope, per-user or per-deployment credentials, spending limits, rate limits, expiration, and rotation policies.
- Add automated secret scanning to pre-commit and CI pipelines to reject future bearer tokens and similar credentials.
- Avoid accepting secrets through command-line arguments where possible because process listings and shell history may expose them; prefer protected environment or secret-store injection.
