T09 · Insecure Skill Coding Practices
- Location
scripts/douyin_diagnosis.py:27- Finding
Hardcoded Shared API Credential
- Content
View full analysis
环境变量 REDFOX_API_KEY > 内置默认密钥""" return cli_key or os.environ.get("REDFOX_API_KEY") or DEFAULT_API_KEY ``` ### Technical Analysis The source contains an operationally formatted RedFox API key and automatically selects it whenever neither a command-line key nor the `REDFOX_API_KEY` environment variable is present. Anyone who can download or inspect the Skill can extract and reuse the credential independently. This also directly contradicts the security guidance in `README.en.md`, which states that keys must not be hardcoded or exposed in source code. Source-repository history and redistributed copies may preserve the credential even after it is removed from the current version. The key is sent to `https://redfox.hk/story/api/dyUser/queryData` through the `X-API-KEY` request header. The audit could not determine the server-side permissions or current validity of the key, so the maximum impact depends on its configured scope. ### Attack Path 1. An attacker downloads the Skill or reads its public source. 2. The attacker extracts `DEFAULT_API_KEY` from `scripts/douyin_diagnosis.py`. 3. The attacker constructs requests to the documented RedFox API endpoint with the extracted value in the `X-API-KEY` header. 4. If the key remains active, the attacker consumes its quota or invokes any other API operations permitted by its server-side scope. 5. Requests may be attributed to the credential owner or the Skill, potentially causing quota exhaustion, service disruption, or unexpected charges. ### Impact Assessment No local operating-system privileges are obtained through this issue. The exposed privilege ...[truncated 373 chars]- Remediation
View remediation
