T09 · Insecure Skill Coding Practices
- Location
SKILL.md:645- Finding
Hardcoded WeCom Webhook Credential
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:645
Vulnerability Type: Hardcoded bearer-style webhook credential
Risk Level: HighVulnerable Code
json "wecom_webhook": "https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=14fb1170-2119-4f29-b400-67da770e3a3c"Technical Analysis
The Skill configuration embeds a complete WeCom webhook URL, including its authentication key, in a distributable project file. The key functions as a bearer-style credential: possession of the URL may be sufficient to submit messages to the associated WeCom group webhook without separate user authentication.
The documentation also defines a scheduled risk-report workflow in
SKILL.md:590-602that is intended to send customer-risk reports to a WeCom group. Those reports may contain tenant identities, contract-expiration information, and financial delinquency data. Although the packaged Python script is only a placeholder and does not currently transmit this information, the exposed credential remains independently reusable if it is active.Attack Path
- An attacker obtains a copy of the Skill package, repository, build artifact, log, or documentation containing
SKILL.md. - The attacker extracts the complete webhook URL and embedded
keyparameter from line 645. - The attacker sends crafted requests directly to the WeCom webhook endpoint.
- If the key remains active, arbitrary supported messages can be posted to the webhook's associated group.
- The attacker may use the trusted integration identity for spam, phishing, misleading operational alerts, or impersonation. If the configuration is reused by the documented workflow, customer-risk reports may also be delivered to an unintended or insufficiently controlled destination.
Impact Assessment
Exploitation does not grant host-level code execution, filesystem access, administrative privileges, or general access to the WeCom tenant. Its scope is limit ...[truncated 653 chars]
- An attacker obtains a copy of the Skill package, repository, build artifact, log, or documentation containing
- Remediation
View remediation
Remediation Suggestions
- Immediately revoke and rotate the disclosed WeCom webhook key.
- Remove the complete webhook URL and all live credentials from
SKILL.md, examples, source history, release artifacts, logs, and generated documentation. - Load the webhook URL at runtime from a secret manager or a protected environment variable, such as
WECOM_WEBHOOK_URL. - Commit only a non-sensitive placeholder, for example:
json "wecom_webhook_env": "WECOM_WEBHOOK_URL" - Prevent recurrence with repository secret scanning, pre-commit checks, CI credential detection, and documented secret-rotation procedures.
- Review WeCom webhook access and delivery logs for unauthorized activity since the key was introduced.
- Limit the webhook's destination and capabilities where supported, and apply network or source restrictions if available.
- Require explicit authorization and destination validation before transmitting customer profiles, delinquency details, contact information, or contract-risk reports.
- Minimize notification contents so group messages contain only the information necessary for the intended operational purpose.
- Add fail-closed behavior so the workflow refuses to transmit reports when the secret is absent, malformed, or associated with an unapproved destination.
