T09 · Insecure Skill Coding Practices
- Location
SKILL.md:27- Finding
Insecure Solicitation of BrowserAct API Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:27-29;scripts/google_maps_api.py:94-97
Vulnerability Type: Credential exposure through insecure user instructions
Risk Level: MediumVulnerable Code
SKILL.md:27-29:markdown Before running, check the `BROWSERACT_API_KEY` environment variable. If not set, do not take other measures; ask and wait for the user to provide it. **Agent must inform the user**: > "Since you haven't configured the BrowserAct API Key, please visit the [BrowserAct Console](https://www.browseract.com/reception/integrations) to get your Key."scripts/google_maps_api.py:94-97:python print("Please follow these steps:", flush=True) print("1. Go to: https://www.browseract.com/reception/integrations", flush=True) print("2. Copy your API Key.", flush=True) print("3. Provide it to me or set it as an environment variable (BROWSERACT_API_KEY).", flush=True)Technical Analysis
The Skill explicitly directs users to provide a BrowserAct API key to the Agent as an alternative to configuring it locally. This violates least-exposure principles because the script only requires the credential through the
BROWSERACT_API_KEYenvironment variable; the Agent does not need to receive the plaintext value in a conversation.A credential submitted through chat can enter conversation history, Agent context, application telemetry, diagnostic logs, or other retained records. Although the script itself places the key only in an HTTPS authorization header and does not print it, the surrounding instructions create a separate credential-disclosure path before execution.
Attack Path
- The Skill detects that
BROWSERACT_API_KEYis not configured. - The user is instructed to obtain and provide the API key to the Agent.
- The user pastes the plaintext key into the conversation.
- The key may be retained in chat history, Agent context, telemetry, or logs.
- A part ...[truncated 619 chars]
- The Skill detects that
- Remediation
View remediation
Remediation Suggestions
- Remove all instructions telling users to provide an API key to the Agent or through chat.
- Require users to configure
BROWSERACT_API_KEYdirectly in the execution environment. - Recommend a local secret manager, protected environment configuration, or platform-provided secret storage.
- Replace the current message with guidance that explicitly warns users not to paste credentials into conversations.
- Ensure the Agent never echoes, logs, persists, or requests the plaintext key.
- If a key has already been disclosed through chat, advise the user to revoke and rotate it.
