T09 · Insecure Skill Coding Practices
- Location
odds_scanner.py:30- Finding
Hardcoded Odds API Credential Exposed in Source Code
- Content
View full analysis
Vulnerability Details
File Location:
odds_scanner.py, lines 30 and 83-86
Vulnerability Type: Hardcoded secret and credential disclosure
Risk Level: HighVulnerable Code
python ODDS_API_KEY = "a977eadc1440ca4b073a6158f52f796a"The credential is subsequently transmitted as a URL query parameter:
python url = (f"https://api.the-odds-api.com/v4/sports/{sport_key}/odds/" f"?apiKey={ODDS_API_KEY}&regions=us&markets=h2h&oddsFormat=decimal") req = urllib.request.Request(url, headers={"User-Agent": "ClawdipusRex/1.0"})Technical Analysis
The source contains a non-placeholder Odds API credential. Anyone who can read or download the Skill can extract and reuse it without authorization.
The key is also included in the request URL rather than an authentication header. Although the request destination,
api.the-odds-api.com, is consistent with the Skill's declared odds-scanning functionality and is not an unrelated exfiltration endpoint, query-string credentials may be captured in application logs, proxy logs, monitoring systems, browser or debugging histories, and error reports.Embedding the credential is unnecessary for the declared functionality. The Skill can instead obtain a user-provided credential from an environment variable or protected configuration file. The current implementation therefore exceeds the minimum secret exposure necessary to perform the task.
Attack Path
- An attacker obtains the distributed Skill package or gains read access to its source.
- The attacker reads
odds_scanner.pyand extracts the plaintext API key from line 30. - The attacker submits requests directly to The Odds API using the exposed credential.
- Requests are attributed to the credential owner's account.
- The attacker can exhaust the account's request quota and may cause billing or service disruption, depending on the associated account plan.
- Additional c ...[truncated 924 chars]
- Remediation
View remediation
Remediation Suggestions
-
Immediately revoke and rotate the exposed Odds API key.
-
Remove the key from source code and repository history.
-
Load the credential from an environment variable, for example:
python ODDS_API_KEY = os.environ.get("ODDS_API_KEY") if not ODDS_API_KEY: raise RuntimeError("ODDS_API_KEY is required") -
Alternatively, use a user-owned configuration file with restrictive filesystem permissions and ensure it is excluded from version control.
-
If The Odds API supports header-based authentication, send the key through the documented authentication header rather than the URL query string.
-
Configure proxies, telemetry, and error handlers to redact authentication values and URL query parameters.
-
Add automated secret scanning to CI and pre-commit checks.
-
Update
SKILL.mdso users must provide their own API credential instead of receiving an embedded credential.
-
