T09 · Insecure Skill Coding Practices
- Location
SKILL.md:70- Finding
Unsafe Handling of Live Stripe API Secret Keys
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 70-71 and 86
Vulnerability Type: Hardcoded and command-line API credentials
Risk Level: HighVulnerable Code
bash curl "https://api.stripe.com/v1/subscriptions?status=active&limit=100&expand[]=data.items.data" \ -u sk_live_YOUR_KEY: | jq 'python stripe.api_key = "sk_live_YOUR_KEY"Technical Analysis
The examples use a placeholder rather than an actual credential, but they instruct users to replace it with a live Stripe secret key. The
curlexample places the credential directly in a command-line argument. Depending on the operating system and execution environment, the resulting secret may be exposed through shell history, process inspection, command auditing, terminal capture, or CI/CD logs.The Python example encourages embedding the live key directly in source code. A user following this pattern could inadvertently commit the credential to version control or expose it through shared files, backups, support bundles, logs, or generated artifacts. Removing a key from the latest revision would not eliminate it from repository history.
This is an insecure credential-handling pattern under
T09: Insecure Skill Coding Practices. No actual live key was found in the audited file.Attack Path
- A user replaces
sk_live_YOUR_KEYwith a valid Stripe secret key. - The user executes the
curlcommand or saves the Python example with the embedded credential. - The credential is retained in shell history, exposed in process or audit data, captured in logs, or committed to a repository.
- An attacker or unauthorized local user obtains access to one of those sources.
- The attacker extracts the Stripe secret and authenticates to the Stripe API.
- The attacker accesses the data and operations permitted by that key until it is revoked or rotated.
Impact Assessment
Successful exploitation could expose ...[truncated 523 chars]
- A user replaces
- Remediation
View remediation
Remediation Suggestions
-
Read the Stripe key from a protected environment variable or secret manager instead of embedding it in source code:
python import os import stripe stripe.api_key = os.environ["STRIPE_API_KEY"] -
Avoid passing the credential directly as a command-line argument. Configure
curlthrough a protected configuration file or use a small client that reads the secret from the environment without printing it. If a configuration file is used, restrict its permissions to the owning user. -
Use a Stripe restricted key granting only the read permissions required for subscription analytics. Do not recommend a full-access live key when read-only access is sufficient.
-
Ensure secrets are masked in CI/CD output and excluded from command tracing, debug logs, notebooks, generated reports, and support bundles.
-
Add secret-bearing files to
.gitignoreand enable automated secret scanning or pre-commit checks. Environment template files should contain variable names only, never real values. -
Document an incident response procedure requiring immediate key revocation and rotation if a credential is entered into shell history, committed to a repository, or otherwise exposed.
-
