T09 · Insecure Skill Coding Practices
- Location
bind_api_key.py:110- Finding
API Key Sent as Knowledge-Base Business Content During Binding
- Content
View full analysis
Dict[str, Any]: """ Call the binding validation endpoint. """ payload = { "content": api_key, "brand_name": api_key, } headers = { "x-api-key": api_key, "Content-Type": "application/json", } try: response = requests.post( BIND_URL, headers=headers, data=json.dumps(payload, ensure_ascii=False).encode("utf-8"), timeout=30, ) ``` ### Technical Analysis The binding operation uses the knowledge-storage endpoint `/openapi/skills/save_content/md`. The complete API key is sent not only in the authentication header, where it may legitimately be required, but also as both the `content` and `brand_name` fields. Credential validation does not require duplicating the secret into business-data fields. Because the selected endpoint is also used by `knowledge_tool.py` to store brand knowledge, the request may cause the API key to be retained as ordinary knowledge-base content, indexed data, application logs, analytics records, or audit records. This behavior exceeds the minimum privileges and data disclosure necessary for the declared binding function. It is also not disclosed in the Skill documentation, which only states that the key is bound and stored in a local `.env` file. ### Attack Path 1. A user invokes `bind_api_key.py --api-key ""`. 2. `request_bind_check()` places the complete secret in: - The `x-api-key` authentication header. - The `content` request field. - The `brand_name` request field. 3. The request is sent to a content-storage endpoint. 4. The remote servic ...[truncated 923 chars]- Remediation
View remediation
