T09 · Insecure Skill Coding Practices
- Location
SKILL.md:31- Finding
API Credential Disclosure Encouraged Through Agent Conversation
- Content
View full analysis
"Since you haven't configured the BrowserAct API Key, please visit the [BrowserAct Console](https://www.browseract.com/reception/integrations) to get your Key." ``` `scripts/amazon_product_search_api.py:97-102`: ```python if not api_key: print("\n[!] ERROR: BrowserAct API Key is missing.", flush=True) print("Please follow these steps:", flush=True) print("1. Go to: https://www.browseract.com/reception/integrations", flush=True) print("2. Copy your API Key.", flush=True) print("3. Provide it to me or set it as an environment variable (BROWSERACT_API_KEY).", flush=True) sys.exit(1) ``` ### Technical Analysis The Skill documentation directs the Agent to ask the user to provide the BrowserAct API key, while the executable script explicitly presents providing the key “to me” as an alternative to configuring an environment variable. This encourages users to disclose a reusable credential through the Agent conversation. The script only requires access to `BROWSERACT_API_KEY` through its process environment. The Agent does not need to read or receive the plaintext credential in conversation. Asking for it therefore exceeds the minimum access necessary for the declared Amazon product-search functionality. Credentials entered into a conversation may be retained in chat history, Agent execution traces, diagnostic records, or other logging systems. The reviewed code does not itself transmit the key to an undeclared endpoint: it uses the key as a Bearer token for the declared H ...[truncated 1474 chars]- Remediation
View remediation
