T09 · Insecure Skill Coding Practices
- Location
scripts/tumblr_post.py:20- Finding
Hard-Coded Tumblr OAuth Credentials Expose Account Access
- Content
View full analysis
Vulnerability Details
File Location:
scripts/tumblr_post.py:20-24; credentials are also disclosed inSKILL.md:20-22
Vulnerability Type: Hard-coded secrets and plaintext credential exposure
Risk Level: HighEvidence
scripts/tumblr_post.py:20-24:python CONSUMER_KEY = "6hFfvv3WkP46yy6Bgif9f8n0rOhli7eOTHOnBJ07PXk7njZrYK" CONSUMER_SECRET = "wJniuQfcmUoDbzq87GNIV6eki4VJsdclU0d3q5k3TgYNZZQgeq" ACCESS_TOKEN = "55OHtil3amJeXLDnTGknXgCGJD7SLM0f09LaS7c0fTkV7w7vAS" ACCESS_TOKEN_SECRET = "WHzIBb01txQwvsbO0T5cD0W46EKkFgBNVXJkCXA9JTTq04554h" BLOG_NAME = "remoneofcourse"SKILL.md:20-22additionally exposes credential material:text Tumblr account: remoneofcourse Consumer Key: 6hFfvv3WkP46yy6Bgif9f8n0rOhli7eOTHOnBJ07PXk7njZrYK Access Token: 55OHtil3amJeXLDnTGknXgCGJD7SLM0f09LaS7c0fTkV7w7vASTechnical Analysis
The Skill embeds a complete Tumblr OAuth 1.0 credential set directly in distributed source code. The consumer secret and access-token secret are not configuration identifiers; they are authentication secrets that must remain confidential. Anyone with read access to the Skill package, a copied archive, build output, logs containing the source, or repository history can recover them without needing access to the original operator's environment.
The credentials are actively consumed by
OAuth1Sessioninscripts/tumblr_post.py:111-114:python tumblr = OAuth1Session( CONSUMER_KEY, client_secret=CONSUMER_SECRET, resource_owner_key=ACCESS_TOKEN, resource_owner_secret=ACCESS_TOKEN_SECRET )The resulting authenticated session creates posts under the configured Tumblr blog. Moving the same strings into another script would allow an unauthorized party to construct equivalent signed requests, subject to the permissions and continued validity of the exposed token.
Because the credentials have been committed to plaintext, merely deleting them from the lates ...[truncated 1591 chars]
- Remediation
View remediation
Remediation Suggestions
-
Revoke and rotate immediately
- Revoke the exposed Tumblr access token and access-token secret.
- Rotate the consumer secret and consumer key where Tumblr supports doing so.
- Treat all values shown in the package and documentation as compromised.
- Review Tumblr account activity for unauthorized posts or API operations.
-
Remove secrets from all tracked content
- Delete credential values from
scripts/tumblr_post.pyandSKILL.md. - Purge them from repository history, release archives, caches, build artifacts, and published Skill packages.
- Be aware that history rewriting does not invalidate previously copied credentials; rotation remains mandatory.
- Delete credential values from
-
Use protected runtime configuration
- Read secrets from environment variables or an operating-system-backed secret manager.
- Fail closed with a clear error when required variables are absent.
- Do not print credentials or include them in exception messages.
Example:
python CONSUMER_KEY = os.environ["TUMBLR_CONSUMER_KEY"] CONSUMER_SECRET = os.environ["TUMBLR_CONSUMER_SECRET"] ACCESS_TOKEN = os.environ["TUMBLR_ACCESS_TOKEN"] ACCESS_TOKEN_SECRET = os.environ["TUMBLR_ACCESS_TOKEN_SECRET"] BLOG_NAME = os.environ["TUMBLR_BLOG_NAME"] -
Reduce credential privileges
- Issue a dedicated token for this Skill.
- Grant only the minimum publishing and read permissions required.
- Avoid sharing tokens between production accounts, users, or unrelated automation.
-
Prevent recurrence
- Add secret scanning to pre-commit hooks and continuous integration.
- Block commits matching OAuth tokens, API keys, and private-key patterns.
- Provide placeholders such as
TUMBLR_ACCESS_TOKENin documentation rather than live values. - Establish scheduled credential rotation and audit logging for automated publishing.
-
