T09 · Insecure Skill Coding Practices
- Location
scripts/search.py:14- Finding
Hardcoded Parallel API Credential Used as an Automatic Fallback
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search.py, line 14
Vulnerability Type: Hardcoded secret / credential exposure
Risk Level: HighVulnerable Code
python API_KEY = os.environ.get("PARALLEL_API_KEY", "y2s_m4er5i6-5qCikOLUtmnkvOYRU24eDphq_jg1")Technical Analysis
A Parallel API credential is embedded directly in the distributed source code. When
PARALLEL_API_KEYis absent, the script automatically authenticates with this credential.Anyone who can download the skill, inspect a deployment artifact, read a source archive, or view repository history can recover the credential. Because the script silently falls back to it, users may also unknowingly submit search queries under the credential owner's account.
The credential cannot be treated as confidential once published. Removing it only from the latest revision is insufficient because it may remain in package copies, caches, forks, logs, and version-control history.
Attack Path
- An attacker downloads or otherwise obtains the skill package.
- The attacker reads line 14 of
scripts/search.pyand extracts the embedded key. - The attacker supplies the key to the Parallel SDK or sends requests directly to the Parallel API.
- Requests are charged to, logged under, and constrained only by the permissions and quotas of the exposed account.
- The attacker can continue consuming the credential until it is revoked or expires.
Alternatively, a user can execute
search.pywithout settingPARALLEL_API_KEY; the script then sends that user's queries through the exposed credential without clearly informing the user.Impact Assessment
A valid exposed key may allow unauthorized Parallel API usage, quota exhaustion, financial charges, service disruption, and access to account-scoped operations permitted to that key. The exact scope depends on server-side permissions assigned by Parallel.
The issue does not directly grant l ...[truncated 191 chars]
- Remediation
View remediation
Remediation Suggestions
-
Revoke and rotate the exposed credential immediately.
-
Remove the fallback value and fail closed when the environment variable is absent:
python API_KEY = os.environ.get("PARALLEL_API_KEY") if not API_KEY: print( "Error: PARALLEL_API_KEY environment variable is required", file=sys.stderr, ) sys.exit(1) -
Purge the secret from version-control history and previously published artifacts where practical.
-
Search account telemetry for unauthorized use, unexpected source addresses, abnormal costs, and quota spikes.
-
Store deployment credentials in a dedicated secret manager or protected environment configuration.
-
Add automated secret scanning and pre-commit or CI checks to prevent future credential publication.
-
Use narrowly scoped, short-lived credentials and configure spending or rate limits where supported.
-
