T09 · Insecure Skill Coding Practices
- Location
scripts/01_fetch_kols.py:28- Finding
Hardcoded Twitter API Credential in Source Code
- Content
View full analysis
Vulnerability Details
File Location:
scripts/01_fetch_kols.py, line 28
Vulnerability Type: Hardcoded secret
Risk Level: HighVulnerable Code
python API_KEY = CONFIG.get( "twitter_api_key", "new1_[REDACTED_EXPOSED_KEY]" ) # Default value for local useThe credential has been redacted from this report to avoid further disclosure. The source file contains the complete value.
Technical Analysis
The script embeds a non-placeholder Twitter API credential as the fallback value for
twitter_api_key. If the configuration entry is absent, the embedded credential is automatically used:python headers = {"x-api-key": API_KEY} response = requests.get(url, headers=headers, timeout=10)Secrets embedded in distributed source code cannot be protected through application access controls. Anyone who can download, inspect, fork, or archive the Skill can recover the credential independently of whether the script executes successfully.
The fallback also causes the application to fail open: a missing configuration does not stop execution but instead silently uses a shared credential. This prevents reliable attribution and permits unrelated users to consume the credential owner's API quota.
Attack Path
- An attacker obtains a copy of the Skill package or its source history.
- The attacker opens
scripts/01_fetch_kols.pyand extracts the fallback API key. - The attacker submits arbitrary requests to the Twitter API provider with the header:
http x-api-key: EXTRACTED_KEY - Requests are charged to, rate-limited against, or logged under the credential owner's account.
- The attacker continues using the key until it is revoked or restricted by the provider.
Impact Assessment
An attacker may obtain the API privileges assigned to the exposed Twitter API key. The demonstrated code uses it to retrieve public tweets, but the ultimate scope depends ...[truncated 518 chars]
- Remediation
View remediation
Remediation Suggestions
- Immediately revoke and rotate the exposed credential.
- Remove the credential from the current source and all repository history, release archives, logs, and build artifacts.
- Do not provide a secret fallback. Fail closed when no credential is configured:
python API_KEY = os.environ.get("TWITTER_API_KEY") if not API_KEY: raise RuntimeError("TWITTER_API_KEY is not configured") - Store production credentials in environment variables, a platform secret store, or a dedicated secrets manager.
- Add secret-scanning controls to CI and pre-commit workflows.
- Restrict the replacement key to only the API endpoints and operations required by the Skill.
- Configure provider-side spending limits, rate limits, expiration, and monitoring.
- Ensure configuration files containing real credentials are excluded from version control and created with restrictive file permissions.
