T09 · Insecure Skill Coding Practices
- Location
SKILL.md:70- Finding
Hard-Coded DashScope API Credential
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 70
Vulnerability Type: Hard-coded secret in published Skill documentation
Risk Level: HighVulnerable Code Snippet:
bash export DASHSCOPE_API_KEY="sk-ec70253d8fb14e53a679726ad2e1563c"Technical Analysis
The complete workflow example embeds a credential-shaped DashScope API key directly in the Skill documentation. Because the key is stored as plaintext in a project file, anyone who can access the Skill package, repository history, distribution archive, or generated audit artifacts may retrieve it.
This is inconsistent with the earlier instruction to obtain the API key from the user at runtime. Secrets must not be included in documentation or source-controlled configuration, even when presented as examples. If the displayed key is valid or can be reactivated, it can be used independently of this Skill to submit authenticated requests to DashScope.
No
curl | bashpipeline or remote script execution was found in the audited file. The ordinarycurlcommands invoke documented API and file-transfer operations rather than downloading and executing code.Attack Path
- An attacker obtains a copy of
SKILL.mdfrom the Skill package, repository, cache, log, or other distribution channel. - The attacker extracts the plaintext value assigned to
DASHSCOPE_API_KEY. - The attacker supplies the key in a DashScope
Authorization: Bearerheader. - If the key remains valid, the attacker submits image-generation or other requests permitted by its associated account and authorization scope.
- The requests consume the victim account's quota and may incur charges or disrupt legitimate use.
This exploitation path does not require local code execution or system privileges; it depends on the exposed key remaining valid.
Impact Assessment
A successful attacker can obtain the DashScope API privileges granted to the exposed key. Potential ...[truncated 288 chars]
- An attacker obtains a copy of
- Remediation
View remediation
Remediation Suggestions
-
Revoke the exposed DashScope API key immediately and issue a replacement through the provider's credential-management interface.
-
Replace the literal secret with a non-secret placeholder:
bash export DASHSCOPE_API_KEY="${DASHSCOPE_API_KEY}"Alternatively, omit the export command and document that the variable must be supplied securely at runtime.
-
Store active credentials in an approved secret manager, protected runtime environment, or platform credential store. Do not place them in Skill files, examples, logs, shell history, or version control.
-
Review repository history, release archives, caches, and published copies for the exposed key. Removing it only from the current file is insufficient if historical copies remain available.
-
Inspect DashScope usage and billing records for unauthorized activity associated with the exposed credential.
-
Restrict replacement credentials to the minimum API permissions and quota needed for image generation.
-
Add automated secret scanning to pre-commit, continuous-integration, and publication workflows to prevent future credential disclosure.
-
