T09 · Insecure Skill Coding Practices
- Location
scripts/amap_key_automator.py:135- Finding
AMAP API Key Disclosed Through Console Output
- Content
View full analysis
Vulnerability Details
File Location:
scripts/amap_key_automator.py, line 135
Vulnerability Type: Plaintext secret disclosure through application logs
Risk Level: MediumVulnerable Code
python try: # Locate the key by finding the row with our key name row_locator = page.locator("tr", has=page.locator("text='lbs-ca-key'")).first # The key is in the second td of that row key_value = await row_locator.locator("td").nth(1).inner_text() key_value = key_value.strip() print(f"Success: Extracted AMAP Key: {key_value}") # Save to .env (Project Root) script_dir = os.path.dirname(os.path.abspath(__file__)) project_root = os.path.dirname(script_dir) env_path = os.path.join(project_root, ".env") with open(env_path, "a", encoding="utf-8") as f: f.write(f"\nAMAP_KEY={key_value}\n")Technical Analysis
The provisioning script prints the complete newly created AMAP API key to standard output. Standard output is frequently retained by terminal recorders, agent execution histories, CI/CD systems, centralized logging platforms, and process supervisors.
The key is a bearer-style credential used by
competitor_analysis.pyto authenticate requests to the AMAP API. Any party able to read retained output can reuse it without access to the original AMAP account. Printing the credential is not required for the declared functionality because the script already writes it to the configured credential file.Attack Path
- A user runs
scripts/amap_key_automator.pyand completes AMAP authentication. - The script creates and extracts a Web Service API key.
- Line 135 writes the complete key to standard output.
- An agent transcript, terminal logger, CI runner, or centralized logging service retains the output.
- A party with access to those logs retrieves the key.
- The party submits authenticated requests to AMAP using the exposed crede ...[truncated 447 chars]
- A user runs
- Remediation
View remediation
Remediation Suggestions
- Remove the statement that prints the complete key.
- If confirmation is necessary, print only a redacted fingerprint, such as the final four characters:
python print(f"Success: AMAP key created: ****{key_value[-4:]}") - Configure execution environments to redact common secret patterns from logs.
- Avoid returning the key in exceptions, status objects, or agent messages.
- Rotate any API key that may already have appeared in retained logs.
- Review and purge accessible historical logs containing the plaintext credential.
