T09 · Insecure Skill Coding Practices
- Location
references/auth.md:13- Finding
Plaintext API Credentials Embedded in Authentication Documentation
- Content
View full analysis
Vulnerability Details
File Location:
references/auth.md, lines 13–15
Vulnerability Type: Hardcoded credentials and plaintext sensitive data
Risk Level: Highmarkdown - `x-app-id`: TinqIbRCZdwzpkaD - `x-app-secret`: BcTmTA6gN8phMvSI2wZj5YO7 二者均为必填。Technical Analysis
The authentication documentation contains a complete application identifier and application secret in plaintext. These values appear to be directly usable in the required
x-app-idandx-app-secretrequest headers.Embedding credentials in a distributable Skill package exposes them to every person or process with access to the package, its source archive, cached copies, or repository history. This also conflicts with the secret-handling guidance in
SKILL.md, which states that secrets must never be printed in full.The bundled OpenAPI specification defines authenticated operations for listing, opening, and closing shops. If the exposed credentials remain valid and an attacker can reach the actual API service, they may use the credentials to invoke those operations.
Attack Path
- An attacker obtains or reads the Skill package.
- The attacker opens
references/auth.mdand extracts the plaintextx-app-idandx-app-secret. - The attacker identifies the actual API base URL through deployment information, local configuration, logs, or related documentation.
- The attacker submits both values as authentication headers.
- The attacker calls
GET /v1/shopsto enumerate accessible shops. - The attacker calls
POST /v1/shops/{id}/openorPOST /v1/shops/{id}/close. - Opening a shop may return Selenium connection details, including an address and port, as defined by the bundled OpenAPI specification.
Impact Assessment
Successful exploitation could provide unauthorized authenticated access within the privileges assigned to the exposed application credentials. Based on the documented endpoints, the poten ...[truncated 480 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke and rotate the exposed application identifier and secret immediately.
- Remove all real credential values from the current package and repository history.
- Replace credentials in documentation with unmistakable placeholders, such as:
text x-app-id: ${KJW_APP_ID} x-app-secret: ${KJW_APP_SECRET} - Store operational credentials in an approved secret manager or dedicated environment variables.
- Ensure credentials are injected only at runtime and are never written to generated commands, logs, transcripts, or error messages in full.
- Add automated secret scanning to the development and release process.
- Restrict the credentials server-side using least privilege, network allowlists, expiration, rotation, and per-client audit logging.
- Review API access logs for unauthorized use of the exposed values.
