T09 · Insecure Skill Coding Practices
- Location
payment.py:11- Finding
Hard-Coded SkillPay API Credential in Distributed Source Code
- Content
View full analysis
Vulnerability Details
File Location:
payment.py, lines 11-18
Vulnerability Type: Hard-coded API secret
Risk Level: HighVulnerable Code
python BILLING_API_URL = "https://skillpay.me" BILLING_API_KEY = "sk_f03aa8f8bbcf79f7aa11c112d904780f22e62add1464e3c41a79600a451eb1d2" SKILL_ID = "ac50f691-5081-4843-9942-bb3955872b23" SKILL_NAME = "whale-alert-monitor" PRICE_PER_CALL = 0.01 # USDT HEADERS = { "X-API-Key": BILLING_API_KEY, "Content-Type": "application/json" }Technical Analysis
A live-looking SkillPay API key is embedded directly in source code distributed with the Skill. Anyone with access to the package can recover and reuse this credential. This also contradicts
_meta.json, which declaresSKILLPAY_API_KEYas the expected credential source.The key is attached to requests made to the balance, charge, and payment-link endpoints. The actual privileges available to an attacker depend on SkillPay's server-side authorization, but client-side secrecy provides no protection once the credential is published.
Attack Path
- An attacker downloads or otherwise obtains the Skill package.
- The attacker reads
payment.pyand extractsBILLING_API_KEY. - The attacker submits requests to the documented SkillPay billing endpoints with the exposed key in the
X-API-Keyheader. - If the service does not strictly bind the key to authorized users, fixed amounts, and the declared Skill ID, the attacker may perform unauthorized balance queries, generate payment links, submit billing requests, or consume the account's quota.
- Requests may appear to originate from the legitimate Skill because they use its credential.
Impact Assessment
The exposed credential may permit unauthorized use of the SkillPay account's billing API privileges. Potential effects include fraudulent or incorrect billing operations, information disclosure through balance queries, payment-link ...[truncated 207 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke and rotate the exposed API key immediately.
- Remove the credential from source code and repository history.
- Load the credential exclusively from
SKILLPAY_API_KEY:python BILLING_API_KEY = os.environ.get("SKILLPAY_API_KEY") if not BILLING_API_KEY: raise RuntimeError("SKILLPAY_API_KEY is required") - Construct authorization headers only after validating that the environment variable is present.
- Store production secrets in the platform's managed secret store rather than configuration files or package metadata.
- Configure SkillPay to bind the credential to the fixed Skill ID, permitted endpoints, expected price, and minimum required operations.
- Add rate limits, request auditing, replay protection, and anomaly alerts on the billing service.
- Avoid using
"anonymous_user"as a billable fallback; require a validated user identity before attempting a charge. - Add automated secret scanning to release and CI pipelines.
