T09 · Insecure Skill Coding Practices
- Location
SKILL.md:22- Finding
Hardcoded MiniMax API Credential in Skill Documentation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a simple UE material-generator note, but it publishes a plaintext MiniMax API key that users should treat as compromised.
Do not install or reuse this skill as-is with the included key. The publisher should revoke and rotate the MiniMax key, replace it with an environment-variable or secret-manager instruction, and ensure any deployed app keeps provider credentials server-side with rate limits and user controls.
SKILL.md:22Hardcoded MiniMax API Credential in Skill Documentation
The skill documentation exposes a live-looking API secret directly in a client-side skill package. Anyone who can read the file can reuse the key to invoke the third-party model API, leading to unauthorized usage, billing abuse, account compromise, and possible access to associated service capabilities or logs.
The entire skill documentation is presented only in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. This creates a natural-language policy concern because it effectively imposes a locale without explicit opt-in or justification.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- `public/` — 静态JSON示例文件
## API配置
- Base: `https://api.minimaxi.com/v1`
- Model: `MiniMax-M2.7`
- Key: `sk-cp-g2MZf43bhLucC0sCMI-BeaXycKl5MDj_dPN_mPKn7IfqlAL1bS8YP-ERiEi9ZJMLu7I2XXIMjw9Xb8x-9iONlnOg24dBV5imId_W5v1oyivKwZCMr7nix6c`
No suspicious patterns detected.