T09 · Insecure Skill Coding Practices
- Location
scripts/build_report.py:125- Finding
Plaintext Administrative Credentials Embedded in Generated Reports
- Content
View full analysis
Vulnerability Details
File Location:
scripts/build_report.py:125
Vulnerability Type: Hardcoded credentials and plaintext sensitive-data exposure
Risk Level: MediumVulnerable Code
python para(doc, "账号:租户=园区智慧应用管理系统,用户=admin,密码=admin123")The report template inserts a tenant identifier, administrative username, and password directly into every generated Word document. Because the values are hardcoded rather than supplied through a protected secret-management mechanism, users may overlook them when adapting or executing the template.
Technical Analysis
Generated
.docxreports are ordinary files that may be shared through email, uploaded to collaboration platforms, committed to repositories, or retained in broadly accessible archives. Embedding authentication secrets in such a document creates a secondary, uncontrolled copy of the credentials.If the hardcoded values are valid in a target deployment, anyone who can read the generated report can recover and attempt them. Even when they are example values, including a recognizable default administrative password encourages insecure credential reuse and can cause operators to distribute real credentials after modifying the template.
Attack Path
- An operator copies or executes the report-generation template without removing the hardcoded account information.
- The script writes the tenant, username, and password into the generated Word report.
- The report is distributed, archived, uploaded, or exposed to a user who is not authorized to receive authentication secrets.
- The recipient extracts the credentials from the document.
- If the credentials remain valid and the target system is reachable, the recipient authenticates as the administrative account.
- The recipient can then exercise all application capabilities granted to that account.
Impact Assessment
The immediate scope is disclosure of the embedded tenant and acco ...[truncated 484 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all passwords from the report template and generated reports.
- Replace the vulnerable line with a redacted account reference, such as
Account: admin (password omitted). - Do not include real credentials in screenshots, test logs, source files, report metadata, or filenames.
- Obtain credentials at runtime through an approved secret manager or protected environment variable when authentication is required. Do not write those values into the report.
- Add a final report-redaction step that detects passwords, tokens, session identifiers, API keys, and other sensitive values before saving or distributing the document.
- Rotate the displayed password if it has ever been valid in any environment, and review previously generated reports for exposure.
- Use a dedicated, least-privileged testing account instead of a general administrative account.
