T09 · Insecure Skill Coding Practices
- Location
payment.py:11- Finding
Hard-Coded SkillPay Billing API Credential
- Content
View full analysis
float: """Query user balance.""" try: resp = requests.get( f"{BILLING_API_URL}/api/v1/billing/balance", params={"user_id": user_id}, headers=HEADERS, timeout=10 ) ``` ### Technical Analysis A secret-looking SkillPay API key is embedded directly in the distributed source code and automatically included in the `X-API-Key` header of billing requests. Anyone with access to the package can extract and reuse this credential independently of the Skill. This implementation contradicts `_meta.json:11-13`, which declares that the billing credential should be supplied through the `SKILLPAY_API_KEY` environment variable: ```json "payment": { "api_key_env": "SKILLPAY_API_KEY", "user_id_env": "SKILLPAY_USER_ID", "required": true } ``` Embedding a shared credential prevents meaningful per-deployment isolation and makes credential rotation difficult. Source-control history, package mirrors, logs, backups, and downstream copies may continue exposing the key even after the current file is changed. The key is transmitted only to the fixed HTTPS endpoint `https://skillpay.me` in the reviewed implementation; no evidence was found that it is deliberately exfiltrated elsewhere. Nevertheless, its publication makes unauthorized direct use possible. ### Attack Path 1. An attacker downloads or otherwise obtains the Skill package. 2. The attack ...[truncated 1059 chars]- Remediation
View remediation
