T09 · Insecure Skill Coding Practices
- Location
SKILL.md:10- Finding
Hardcoded Grocy API Key in Skill Configuration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10–13
Vulnerability Type: Hardcoded authentication secret
Risk Level: HighVulnerable Code
markdown ## Configuration | Variable | Value | |----------|-------| | URL | `http://localhost:14611` | | API Key | `mz43yGJzBKfwZdSOwG5EdnKPRrKnCbkGrEFbxXYv2JF61tQ9Mj` |Technical Analysis
The Skill stores a reusable Grocy API key directly in a versioned Markdown file. Any user, process, distribution recipient, archive, or log with access to the Skill package can recover the credential without authentication.
The key is intended for use in the
GROCY-API-KEYrequest header. The documented Grocy interface includes read operations and state-changing operations such as consuming, opening, transferring, adding, and inventory-auditing products. Consequently, the exposed value is not merely configuration metadata; it is an authentication credential capable of authorizing access within the permissions assigned to the key.The configured service uses unencrypted HTTP. Its loopback address limits direct network exposure, but it does not protect requests from untrusted local processes or from an attacker who obtains a request-forwarding, proxying, or server-side request forgery capability that can reach the host's loopback interface.
Attack Path
- An attacker obtains read access to the Skill package, a repository copy, an archive, or another artifact containing
SKILL.md. - The attacker extracts the plaintext API key from line 13.
- The attacker gains a request execution path on the Grocy host or another capability that can reach
http://localhost:14611. - The attacker sends requests containing:
http GROCY-API-KEY: mz43yGJzBKfwZdSOwG5EdnKPRrKnCbkGrEFbxXYv2JF61tQ9Mj - The attacker invokes Grocy endpoints allowed by the key, potentially reading inventory information or modifying stock and battery records.
Exploitat ...[truncated 885 chars]
- An attacker obtains read access to the Skill package, a repository copy, an archive, or another artifact containing
- Remediation
View remediation
Remediation Suggestions
- Revoke and rotate the exposed API key immediately; removal from the current file does not invalidate copies already distributed.
- Replace the literal credential with a runtime reference such as
$GROCY_API_KEY. - Load the secret from a protected environment variable, operating-system credential store, or dedicated secret manager.
- Remove the credential from repository history, release archives, cached artifacts, logs, and documentation where feasible.
- Restrict access to secret-bearing configuration with least-privilege file permissions.
- Assign the replacement key only the minimum Grocy permissions required by the Skill, if Grocy's authorization model supports scoped credentials.
- Keep the service bound to a trusted interface and prevent untrusted workloads from accessing the loopback endpoint.
- Use HTTPS with certificate validation if the API is ever exposed beyond a strictly trusted loopback context.
- Add automated secret scanning to development and release workflows to block future committed credentials.
- Use placeholders rather than real credentials in all examples and documentation.
