T09 · Insecure Skill Coding Practices
- Location
scripts/hotel_compare.py:19- Finding
Hard-Coded Shared Proxy Authentication Token
- Content
View full analysis
Vulnerability Details
File Location:
scripts/hotel_compare.py, lines 19–20, 37–42, 50–51, and 57–62
Vulnerability Type: Hard-coded authentication credential
Risk Level: HighVulnerable Code
python PROXY_URL = "https://1439498936-4wdncmn2oj.ap-guangzhou.tencentscf.com" PROXY_TOKEN = "tp_8k2mX9vQ4z"python req = urllib.request.Request( PROXY_URL, data=body, headers={"Content-Type": "application/json", "X-Proxy-Token": PROXY_TOKEN}, method="POST" )python TOURMIND_PROXY = "https://1439498936-6cmx3jxanz.ap-guangzhou.tencentscf.com" TOURMIND_TOKEN = "tp_8k2mX9vQ4z"python req = urllib.request.Request( TOURMIND_PROXY, data=body, headers={"Content-Type": "application/json", "X-Proxy-Token": TOURMIND_TOKEN}, method="POST" )Technical Analysis
The Skill embeds a shared proxy authentication token directly in its distributed Python source. Anyone who can download or inspect the package can recover the token without invoking the Skill.
The
_proxyand_tourmind_proxyfunctions place this token in theX-Proxy-Tokenheader when authenticating to two publisher-operated Tencent Cloud Function endpoints. AlthoughSKILL.mddeclaresPROXY_TOKENandHOTEL_COMPARE_PROXY_URLas environment-based configuration, the implementation does not read those environment variables and unconditionally uses the embedded endpoint and token.Sending the token to its intended hotel proxy is not evidence of credential exfiltration. However, distributing an authentication credential in source code destroys its confidentiality and allows unrelated package recipients to reuse it outside the intended Skill workflow. The server-side scope and validity of the token were not verified during this static audit.
Attack Path
- An attacker downloads or otherwise obtains read access to the public Skill package.
- The attacker reads `scripts/hote ...[truncated 1139 chars]
- Remediation
View remediation
Remediation Suggestions
- Immediately revoke and rotate the exposed token, treating it as compromised.
- Remove all authentication credentials from source code and package history.
- Load the proxy URL and token from
HOTEL_COMPARE_PROXY_URLandPROXY_TOKEN, or retrieve them from an appropriate secret manager at runtime. - Fail safely when required credentials are absent rather than falling back to a shared embedded secret.
- Prefer per-user or per-installation credentials over a single credential shared by every package recipient.
- Issue short-lived, narrowly scoped tokens that authorize only the required hotel-search routes.
- Enforce server-side route authorization, request quotas, rate limits, anomaly monitoring, and prompt token revocation.
- Add automated secret scanning to the release process to prevent credentials from being committed or packaged again.
