T09 · Insecure Skill Coding Practices
- Location
configs/config.yaml:1- Finding
Bundled SM4 key enables forged payment credentials
- Content
View full analysis
tuple: config = load_config() sm4_key_b64 = config.get("crypto", {}).get("sm4_key") if not sm4_key_b64: return ("ERROR", "配置文件缺少 crypto.sm4_key") try: sm4_key = base64.b64decode(sm4_key_b64) except Exception: return ("ERROR", "crypto.sm4_key 必须是有效的 Base64 编码") if not is_valid_key(sm4_key): return ("ERROR", "SM4 密钥必须为 16 字节") try: decrypted = sm4_decrypt(credential, sm4_key) except Exception as e: return ("ERROR", f"支付凭证解密失败: {e}") pay_status = "PENDING" try: root = json.loads(decrypted) pay_status = root.get("payStatus", "PENDING") except Exception: pass if pay_status.upper() != "SUCCESS": return (pay_status, f"支付未成功,状态: {pay_status}") return ("SUCCESS", "") ``` ### Technical Analysis The symmetric key used to authenticate payment credentials is distributed in the project configuration and duplicated in executable test code. Any party able to inspect the Skill package can recover the key. Payment acceptance is based on whether data decrypted with this shared key contains a successful status. Because possession of a symmetric key permits both encryption and decryption, users can construct credentials that the verifier cannot distinguish from credential ...[truncated 823 chars]- Remediation
View remediation
