T09 · Insecure Skill Coding Practices
- Location
fetch-earnings.js:188- Finding
Cross-provider API credential disclosure through unsafe environment-variable fallback
- Content
View full analysis
Vulnerability Details
File Location:
fetch-earnings.js:188-199
Vulnerability Type: Cross-provider credential disclosure
Risk Level: HighVulnerable Code
javascript const apiKey = (process.env.ZAI_API_KEY ?? process.env.OPENAI_API_KEY ?? '').trim(); if (!apiKey) { return text; // No API key; return the original text } try { const resp = await fetch('https://open.bigmodel.cn/api/paas/v4/chat/completions', { method: 'POST', headers: { 'Content-Type': 'application/json', 'Authorization': `Bearer ${apiKey}` },Technical Analysis
The translation function first attempts to read
ZAI_API_KEY, but falls back toOPENAI_API_KEYwhen the provider-specific key is unavailable. It then sends the selected value as a bearer credential tohttps://open.bigmodel.cn.An OpenAI API key is intended for OpenAI-controlled endpoints and is unrelated to the declared BigModel/GLM translation provider. Forwarding that credential to another provider violates credential isolation and least-privilege principles. The network request itself is necessary for the optional translation feature, but access to
OPENAI_API_KEYis not necessary and exceeds the minimum privileges required by the Skill.The behavior is triggered automatically by commands that translate returned financial content. It does not require the user to explicitly authorize sending an OpenAI credential to BigModel.
Attack Path
- A user or agent environment contains a valid
OPENAI_API_KEY. - The environment does not contain
ZAI_API_KEY, or it is unavailable to the process. - The user invokes a translation-capable operation such as
calendar,news,summary, orcheckwithout--no-translate. translateToChinese()selectsOPENAI_API_KEYthrough the fallback expression.- The function places that key in the HTTP
Authorizationheader. - The credential is transmitted to `open.bigm ...[truncated 717 chars]
- A user or agent environment contains a valid
- Remediation
View remediation
Remediation Suggestions
-
Remove the
OPENAI_API_KEYfallback and accept only the credential intended for the BigModel/GLM endpoint:javascript const apiKey = (process.env.ZAI_API_KEY ?? '').trim(); -
Fail closed or return untranslated content when
ZAI_API_KEYis absent. Never substitute a credential belonging to a different provider. -
Use explicit provider-specific configuration that binds each credential to an allowlisted hostname.
-
Document exactly which endpoint receives the key and the financial text submitted for translation.
-
Avoid logging authorization headers or provider error responses that could contain credential-related details.
-
Revoke and rotate any
OPENAI_API_KEYthat may already have been exposed through this code path. -
Add an automated test confirming that
OPENAI_API_KEYis never read or transmitted by the GLM translation function.
-
