T09 · Insecure Skill Coding Practices
- Location
scripts/football_query.py:25- Finding
API Credential Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This football-query skill is coherent, but it needs Review because it sends the user's Juhe API key over plaintext HTTP and documents weak key-handling options.
Review before installing. The skill does not show hidden persistence or unrelated data access, but it should be changed to HTTPS before use, and users should avoid passing the API key on the command line or storing it in the skill directory. Prefer a runtime environment variable or secret manager, and rotate any key already used through the plaintext HTTP version.
scripts/football_query.py:25API Credential Transmitted over Plaintext HTTP
scripts/football_query.py:238API Key Exposure through Command-Line Arguments
scripts/football_query.py:288Duplicate API Requests Unnecessarily Retransmit the Credential
The skill advises storing the API key in a .env file under the scripts directory, which can lead to accidental exposure through source control, packaging, backups, or overbroad file access by tools. In a skill context that already implies file-read capability, encouraging on-disk secret storage increases the chance the credential is unintentionally accessed or disclosed.
# 方式一:环境变量(推荐,一次配置永久生效)
export JUHE_FOOTBALL_KEY=你的 AppKey
# 方式二:.env 文件(在脚本目录创建)
echo "JUHE_FOOTBALL_KEY=你的 AppKey" > scripts/.env
# 方式三:每次命令行传入
The examples show passing the API key directly on the command line, which commonly exposes secrets via shell history, process listings, audit logs, and job runners. This is a well-known credential-handling weakness and is unnecessary when environment variables are already supported.
export JUHE_FOOTBALL_KEY=你的 AppKey
# 方式二:.env 文件(在脚本目录创建)
echo "JUHE_FOOTBALL_KEY=你的 AppKey" > scripts/.env
# 方式三:每次命令行传入
python scripts/football_query.py --key 你的 AppKey --type yingchao
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
API Key 配置(任选其一,优先级从高到低):
1. 命令行参数:python football_query.py --key your_api_key ...
2. 环境变量:export JUHE_FOOTBALL_KEY=your_api_key
3. 脚本同目录的 .env 文件:JUHE_FOOTBALL_KEY=your_api_key
免费申请 API Key: https://www.juhe.cn/docs/api/id/90
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
API Key 配置(任选其一,优先级从高到低):
1. 命令行参数:python football_query.py --key your_api_key ...
2. 环境变量:export JUHE_FOOTBALL_KEY=your_api_key
3. 脚本同目录的 .env 文件:JUHE_FOOTBALL_KEY=your_api_key
免费申请 API Key: https://www.juhe.cn/docs/api/id/90
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if env_key:
return env_key
env_file = Path(__file__).parent / ".env"
if env_file.exists():
for line in env_file.read_text(encoding="utf-8").splitlines():
line = line.strip()
The skill advertises capabilities that imply reading environment variables, local files, and making network requests, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens reviewability and least-privilege controls, making it harder for a host agent or user to understand what the skill can access before execution.
The documentation instructs users to send the API key in a URL over plain HTTP, which exposes the secret to interception by network observers, proxies, logs, and browser or shell history. Because the key is transmitted as a query parameter, leakage risk is even higher than with a header or request body.
The script sends the API key as a URL query parameter over plain HTTP to apis.juhe.cn, which exposes the credential to network interception and tampering by any attacker on the path. Because this is an agent skill that may run in varied environments, transmitting secrets without TLS materially increases the chance of credential theft and malicious response manipulation.
The file consistently presents the skill description, setup steps, and operating guidance only in Chinese. This effectively forces a specific language/locale without documenting that limitation or offering a language choice.
All natural-language help text, errors, and usage instructions are hard-coded in Chinese, and there is no option for users to select another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
The comment at L296 suggests the program is merely outputting the JSON form of the already obtained result. Instead, L299-L302 issues a second network request by calling query_ranking/query_matches again, which adds an extra side effect and may return different data from the human-readable output above.
No suspicious patterns detected.