T09 · Insecure Skill Coding Practices
- Location
SKILL.md:20- Finding
Hard-Coded Shared MCP Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20-32
Vulnerability Type: Hard-coded credentials in configuration documentation
Risk Level: MediumVulnerable Code
json "mcp": { "servers": { "engine_mcp_server": { "url": "https://mcp.hzyotoy.com/engine/mcp", "headers": { "Authorization": "Aksk Mu4OfFXJSPyWXGv3", "appid": "mcpclient001" } } } }The same credential-bearing configuration is duplicated at lines 52-66.
Technical Analysis
The Skill embeds a reusable authorization value and application identifier directly in its configuration instructions. Any person who can access the Skill can extract these values and submit requests to the configured MCP endpoint under the shared client identity.
Static shared credentials provide poor isolation and attribution. Rotation requires modifying every deployed configuration, while revoking the credential can disrupt all users who copied the example. The credential's exact server-side permissions cannot be established from the audited file, so access beyond the privileges granted to this identity is not asserted.
Attack Path
- An attacker obtains a copy of
SKILL.md. - The attacker extracts the
Authorizationandappidheader values. - The attacker sends requests directly to
https://mcp.hzyotoy.com/engine/mcpwith those headers. - If the server still accepts the credential, requests are processed under the shared client identity.
- The attacker can consume or misuse whatever MCP functionality, quota, and data access that identity is authorized to use.
Impact Assessment
Successful exploitation could permit unauthorized use of the MCP service within the exposed credential's existing privilege scope. Potential effects include quota consumption, service abuse, weak request attribution, exposure of resources accessible to the shared identity, and operational disr ...[truncated 175 chars]
- An attacker obtains a copy of
- Remediation
View remediation
Remediation Suggestions
- Immediately revoke and rotate the exposed authorization credential.
- Remove all live credentials from
SKILL.mdand its configuration examples. - Replace secret values with explicit placeholders, such as
${ENGINE_MCP_TOKEN}and${ENGINE_MCP_APP_ID}. - Require each installation or user to obtain an individual credential through a trusted provisioning process.
- Store secrets in a protected secret manager, operating-system credential store, or environment variable rather than source-controlled files.
- Use short-lived, narrowly scoped tokens with server-side expiration and revocation support.
- Apply rate limits, audit logging, and per-client attribution at the MCP service.
- Review service logs for unauthorized use of the exposed identity.
- Add automated secret scanning to the publication or review workflow to prevent recurrence.
