T09 · Insecure Skill Coding Practices
- Location
scripts/code_review.py:8- Finding
Hard-Coded Gemini API Credential Exposed in Source Code
- Content
View full analysis
Vulnerability Details
File Location:
scripts/code_review.py, lines 8-14
Vulnerability Type: Hard-coded secret and credential exposure
Risk Level: HighVulnerable Code
python GEMINI_API_KEY = os.environ.get("GEMINI_API_KEY", "AIzaSyDe5i94YxqNZ9OT7mFeuotgfttRmDQ7tz0") GEMINI_URL = "https://generativelanguage.googleapis.com/v1beta/models/gemini-2.5-flash:generateContent" def call_gemini(prompt: str) -> str: """Call Gemini API.""" import urllib.request url = f"{GEMINI_URL}?key={GEMINI_API_KEY}"Technical Analysis
The program contains a live-format Gemini API key as the default value used when the
GEMINI_API_KEYenvironment variable is absent. Because the credential is distributed with the source code, any person who obtains the Skill package can extract and reuse it.The credential is also placed in the request URL query string. URLs can be captured by application diagnostics, proxy logs, monitoring systems, or exception reports, creating additional opportunities for credential disclosure.
Attack Path
- An attacker downloads or otherwise obtains a copy of the Skill package.
- The attacker opens
scripts/code_review.pyand extracts the fallback API key from line 8. - The attacker submits requests directly to the Gemini API using the exposed credential.
- Requests continue consuming the credential owner's quota or billable allowance until the key is restricted or revoked.
- If URLs are logged by surrounding infrastructure, additional parties with log access may recover the same credential.
Impact Assessment
Exploitation does not grant local operating-system privileges. It grants unauthorized use of the external API permissions associated with the exposed key. The resulting scope may include quota consumption, financial cost, service disruption through quota exhaustion, and reputational or operational impact. Actual access is limited by the API key ...[truncated 51 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke and rotate the exposed API key immediately.
- Remove every fallback credential from the source code.
- Require
GEMINI_API_KEYto be supplied through an environment variable or dedicated secret manager, and terminate with a clear error when it is unavailable. - Apply provider-side restrictions, including API restrictions, quota limits, and any supported source restrictions.
- Avoid placing credentials in URL query parameters where the provider supports a safer authentication header or credential mechanism.
- Search repository history, release artifacts, logs, and package archives for the exposed key and remove or sanitize retained copies where feasible.
- Add automated secret scanning to development and release workflows.
