T09 · Insecure Skill Coding Practices
- Location
scripts/mmsearch.py:9- Finding
Hard-Coded MiniMax API Credential in Source Code
- Content
View full analysis
Vulnerability Details
File Locations:
scripts/mmsearch.py:9scripts/mmvision.py:9
Vulnerability Type: Hard-coded secret / plaintext API credential
Risk Level: HighAffected code in
scripts/mmsearch.py:python # Set environment os.environ["MINIMAX_API_KEY"] = "[REDACTED HARDCODED sk-cp- CREDENTIAL]" os.environ["MINIMAX_API_HOST"] = "https://api.minimaxi.com"Affected code in
scripts/mmvision.py:python # Set environment os.environ["MINIMAX_API_KEY"] = "[REDACTED HARDCODED sk-cp- CREDENTIAL]" os.environ["MINIMAX_API_HOST"] = "https://api.minimaxi.com"The credential value is redacted in this report to prevent further disclosure. The audited source contains the complete plaintext value.
Technical Analysis
Both executable scripts embed the same credential-shaped MiniMax API key directly in source code. Anyone who can read the distributed project, a source archive, repository history, logs containing the source, or a deployed copy can recover this credential without authentication.
The scripts place the credential in the global process environment. They subsequently copy that complete environment into the spawned third-party MCP process. This makes the credential accessible not only to the two scripts, but also to the dynamically executed
minimax-coding-plan-mcppackage.Hard-coded secrets cannot be independently protected, rotated, or scoped per installation. Even if the key is removed from the latest source revision, it must be treated as compromised if it has appeared in any distributed version or repository history.
Attack Path
- An attacker obtains a copy of the Skill package or gains read access to its source.
- The attacker opens either
scripts/mmsearch.pyorscripts/mmvision.py. - The attacker extracts the plaintext value assigned to
MINIMAX_API_KEY. - The attacker configures an external client with the extracted key and the confi ...[truncated 768 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke the exposed credential immediately and generate a replacement. Do not merely delete it from the current files.
- Remove the credential from all source files, release archives, build artifacts, documentation, and version-control history.
- Require
MINIMAX_API_KEYto be supplied through a protected runtime environment or secret manager:python api_key = os.environ.get("MINIMAX_API_KEY") if not api_key: print("MINIMAX_API_KEY is required", file=sys.stderr) sys.exit(1) - Use separate, least-privilege credentials for development, testing, and production installations.
- Apply server-side quota, capability, expiration, and source restrictions where MiniMax supports them.
- Add automated secret scanning to development and release pipelines and block commits containing credential patterns.
- Review provider access and usage logs for unauthorized activity involving the exposed key.
- Avoid passing the entire parent environment to child processes. Construct a minimal environment containing only required variables.
