T09 · Insecure Skill Coding Practices
- Location
handler.py:11- Finding
Hard-Coded SkillPay API Credential
- Content
View full analysis
Vulnerability Details
File Location:
handler.py:11andSKILL.md:21
Vulnerability Type: Hard-coded secret exposure
Risk Level: HighVulnerable Code
handler.py:11:python SKILLPAY_API_KEY = "sk_93c5ff38cc3e6112623d361fffcc5d1eb1b5844eac9c40043b57c0e08f91430e"SKILL.md:21:markdown - API Key: sk_93c5ff38cc3e6112623d361fffcc5d1eb1b5844eac9c40043b57c0e08f91430eThe credential is subsequently transmitted in two locations in the same request:
python payload = { "api_key": SKILLPAY_API_KEY, "user_id": user_id, "amount": PRICE_USDT, "skill_id": SKILL_ID, "currency": "USDT", "description": "News summary query" } headers = {"Content-Type": "application/json", "X-API-Key": SKILLPAY_API_KEY}Technical Analysis
A live-looking SkillPay API credential is embedded directly in both the source code and user-facing documentation. Anyone who can download, inspect, clone, or otherwise access the project can recover the credential without authentication.
Hard-coded credentials cannot be protected through ordinary file permissions once a package is distributed. The same credential is also placed in both the JSON request body and the
X-API-Keyheader, unnecessarily increasing its exposure to request logging, debugging systems, proxies, and application telemetry.Attack Path
- An attacker obtains or inspects the project package.
- The attacker reads
SKILL.mdorhandler.pyand extracts the SkillPay API key. - The attacker constructs requests to the SkillPay billing API using the exposed credential.
- If the credential remains active and has sufficient permissions, the attacker acts under the Skill's API identity.
- The attacker may generate unauthorized billing operations or consume API resources until the key is revoked.
Impact Assessment
The exposed credential may permit unauthorized access to operations available to ...[truncated 457 chars]
- Remediation
View remediation
Remediation Suggestions
-
Revoke the exposed API key immediately and issue a replacement.
-
Remove the credential from both
handler.pyandSKILL.md. -
Load the replacement credential from an environment variable or managed secret store:
python import os SKILLPAY_API_KEY = os.environ["SKILLPAY_API_KEY"] -
Validate at startup that the secret is present, but never print its value.
-
Transmit the credential only through the authentication mechanism required by SkillPay; do not duplicate it in the request body unless the verified API specification explicitly requires this.
-
Configure log redaction for authentication headers and sensitive request fields.
-
Restrict the replacement key to the minimum required operations and apply billing, rate, and source restrictions where supported.
-
Review repository history and distributed package versions for prior exposure.
-
Add automated secret scanning to the development and release process.
-
