T09 · Insecure Skill Coding Practices
- Location
SKILL.md:19- Finding
Hardcoded SkillPay API Key Exposed in Skill Documentation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:19
Vulnerability Type: Hardcoded API credential
Risk Level: HighVulnerable Code:
markdown - **API Key**: `sk_3bf4e74479614724623768f5269c68251b09adf555a891eda68dbdfeac108f01`Technical Analysis
A secret-shaped SkillPay API key is embedded directly in documentation distributed with the skill. Any party able to download, inspect, clone, or otherwise access the skill can recover the credential without authentication or specialized tooling.
Secrets must not be stored in source files or documentation because repository access controls, package distribution, caches, forks, logs, and version history can expose them beyond their intended environment. No source code in the audited project transmits this key, and the audit did not verify whether the credential remains active. Nevertheless, its explicit publication must be treated as credential compromise.
Attack Path
- An attacker obtains or downloads the skill package.
- The attacker opens
SKILL.mdand copies the API key from line 19. - The attacker identifies the associated SkillPay service from the adjacent documentation.
- If the key is active, the attacker submits authenticated requests directly to the service using the exposed credential.
- Those requests may consume the associated account's quota or balance and may continue until the credential is revoked, expires, or is otherwise restricted.
Impact Assessment
If valid, the exposed credential may permit unauthorized use of the API privileges assigned to the key. Potential impact includes fraudulent paid calls, quota or balance consumption, service abuse attributed to the legitimate account, and loss of control over activity performed under that credential.
The obtainable privileges are limited to those granted to the API key by SkillPay. The audited project provides no evidence that the key grants local system access, admini ...[truncated 72 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke the exposed API key immediately and issue a replacement only if the integration still requires one.
- Remove the credential from
SKILL.mdand from all published package versions, repository history, forks, build artifacts, caches, and documentation mirrors under the maintainer's control. - Replace the literal value with a non-secret placeholder such as
SKILLPAY_API_KEY. - Require operators to provide credentials through a protected environment variable or dedicated secret-management system at runtime.
- Ensure credentials are never printed in logs, generated responses, error messages, examples, or diagnostic output.
- Restrict replacement credentials to the minimum required scopes, set spending or quota limits, and configure expiration and rotation where supported.
- Review provider-side usage records for requests made with the exposed key and investigate unexpected charges or activity.
- Add automated secret scanning to commit hooks and CI pipelines to prevent future credential publication.
