T09 · Insecure Skill Coding Practices
- Location
SKILL.md:216- Finding
Unsafe API Key Storage and Transmission Guidance
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 216-233
Vulnerability Type: API key exposure through source-code embedding and URL query parameters
Risk Level: LowVulnerable Snippet
The following is an English rendering of the audited documentation:
markdown https://restapi.amap.com/v3/geocode/geo?address={address}&key={API_KEY} https://restapi.amap.com/v3/direction/driving?origin={longitude,latitude}&destination={longitude,latitude}&key={API_KEY} https://restapi.amap.com/v3/direction/driving?origin={origin}&destination={destination}&waypoints={waypoints}&key={API_KEY} To configure the Amap API key: - Environment variable: `AMAP_WEBSERVICE_KEY` - Or use it directly in codeTechnical Analysis
The Skill documentation explicitly permits placing the Amap API key directly in application code. Secrets embedded in source code can be disclosed through source repositories, packaged Skill artifacts, backups, debugging output, or accidental file sharing.
The documented API requests also transmit the key as a URL query parameter. Although this is part of the external API's documented request format, complete URLs may be captured by application logs, proxy logs, monitoring systems, browser history, or diagnostic traces. Any component recording an unredacted request URL could therefore expose the key.
No actual API key was found in the audited project, so exploitation depends on a user following the unsafe configuration guidance or logging complete request URLs.
Attack Path
- An operator follows the documentation and embeds an Amap API key directly in code, or deploys requests with unredacted URL logging.
- The source file, packaged Skill, repository history, application log, proxy log, or diagnostic trace becomes accessible to another party.
- The other party extracts the API key from the source or the
keyquery parameter. - The exposed key is used ...[truncated 752 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the recommendation to place the API key directly in source code.
- Require the key to be supplied through
AMAP_WEBSERVICE_KEYor a managed secret store. - Ensure that source files, configuration templates, examples, and cached data never contain real keys.
- Configure application, proxy, and monitoring systems to redact the
keyquery parameter before storing request URLs. - Disable verbose HTTP logging in production unless sensitive query parameters are reliably filtered.
- Apply the narrowest available API, service, source-address, domain, quota, and usage restrictions to the key.
- Add documented procedures for key revocation and rotation.
- Add secret scanning to repository and release workflows to detect accidentally committed Amap keys.
- If a key has previously been embedded in source or written to logs, rotate it and remove it from repository history and retained logs.
