T09 · Insecure Skill Coding Practices
- Location
SKILL.md:46- Finding
API Key Exposed Through an MCP URL Query Parameter
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:46,README.en.md:59, andREADME.cn.md:59
Vulnerability Type: API credential transmitted and stored in a URL query parameter
Risk Level: MediumVulnerable Code
SKILL.md:42-48:json { "mcpServers": { "scholarplot-sci-figure": { "url": "https://figure.thirdme.com/api/mcp-sse?key=YOUR_API_KEY" } } }README.en.md:55-61:json { "mcpServers": { "scholarplot-sci-figure": { "url": "https://figure.thirdme.com/api/mcp-sse?key=YOUR_API_KEY" } } }README.cn.md:55-61:json { "mcpServers": { "scholarplot-sci-figure": { "url": "https://figure.thirdme.com/api/mcp-sse?key=YOUR_API_KEY" } } }Technical Analysis
The documented configuration instructs users to replace
YOUR_API_KEYwith a real credential embedded directly in the MCP endpoint's query string. Although HTTPS protects the URL while it is transmitted over the network, it does not prevent the complete URL from being retained by components that process or display it.Query strings may be exposed through MCP client diagnostics, application logs, reverse-proxy access logs, network-monitoring systems, configuration backups, screenshots, support bundles, crash reports, or accidentally published configuration files. Any component that records the full endpoint URL may consequently record the API key.
The documentation states that the key is associated with the user's subscription and usage quota. Therefore, possession of a disclosed key may permit an unauthorized party to authenticate to the ScholarPlot service and consume resources associated with the affected account.
Attack Path
- A user obtains a valid ScholarPlot API key.
- Following the supplied instructions, the user places the key in the MCP endpoint URL inside an MCP client configuration file.
- The complete URL ...[truncated 1196 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace query-string authentication with an
Authorizationheader, such as a bearer token, if supported by the MCP client and service. - Store the API key in an operating-system credential store, MCP secret field, or environment variable rather than directly in the endpoint URL.
- Update all English and Chinese configuration examples so that they do not instruct users to interpolate secrets into URLs.
- Configure MCP clients, servers, reverse proxies, monitoring systems, and support-bundle generators to redact authentication values and sensitive query parameters.
- Ensure configuration files containing credentials are excluded from version control, restricted with least-privilege filesystem permissions, and omitted from diagnostic exports.
- Rotate any key that may already have appeared in logs, screenshots, public repositories, or shared configuration files.
- Add server-side key revocation, scoped permissions, short-lived credentials where feasible, usage alerts, and rate limits to reduce the impact of credential disclosure.
- Replace query-string authentication with an
