T09 · Insecure Skill Coding Practices
- Location
scripts/flight_delay_compensation.py:15- Finding
Hard-Coded Proxy Authentication Token
- Content
View full analysis
Vulnerability Details
File Location:
scripts/flight_delay_compensation.py, lines 15–16 and 218–225
Vulnerability Type: Hard-coded credential
Risk Level: HighVulnerable Code
python SCF_PROXY_URL = "https://1439498936-eqcpuaevzz.ap-guangzhou.tencentscf.com" PROXY_TOKEN = os.environ.get("PROXY_TOKEN", "tp_8k2mX9vQ4z")The credential is subsequently transmitted as an authentication header:
python req = urllib.request.Request( SCF_PROXY_URL, data=body, headers={ 'X-Proxy-Token': PROXY_TOKEN, 'Content-Type': 'application/json' }, method='POST' )Technical Analysis
The source code embeds a proxy authentication token as the default value of
PROXY_TOKEN. Because the project is distributed to users, anyone who can obtain the package can read and reuse this credential. Supporting an environment variable does not protect the secret because the embedded token remains active whenever that variable is absent.The token is sent to a fixed Tencent Cloud Function endpoint in the
X-Proxy-Tokenheader. TLS protects it in transit but does not address disclosure through the source code. Effective protection depends on the proxy enforcing narrow authorization, rate limits, expiration, and per-user isolation; those server-side controls cannot be verified from this project.Attack Path
- An attacker downloads or otherwise obtains the Skill package.
- The attacker reads
scripts/flight_delay_compensation.pyand extracts the proxy URL and fallback token. - The attacker constructs HTTPS requests to the exposed proxy endpoint.
- The attacker supplies the extracted value in the
X-Proxy-Tokenheader. - If the token remains valid, the attacker invokes operations allowed by the proxy, potentially outside normal Skill usage.
- The attacker may automate requests to consume quotas, generate service costs, or disrupt availability.
Impact Assessment
Successful exploitation grants the attacker ...[truncated 512 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke and rotate the exposed token immediately; assume it has already been disclosed.
- Remove the hard-coded fallback and fail securely when
PROXY_TOKENis unavailable:
python PROXY_TOKEN = os.environ.get("PROXY_TOKEN") if not PROXY_TOKEN: return { "code": -1, "message": "PROXY_TOKEN is not configured" }- Provision credentials through a supported secret manager or protected runtime configuration rather than source files, metadata, documentation, command-line arguments, or logs.
- Replace the shared static credential with per-user or per-installation credentials that are scoped, revocable, and short-lived.
- Enforce server-side authorization for every permitted request type instead of relying only on possession of the token.
- Apply rate limits, quotas, anomaly detection, and cost alerts per credential and source.
- Restrict the proxy to the minimum required upstream operation and validate all request parameters server-side.
- Review proxy access logs for prior unauthorized use of the disclosed credential.
- Add automated secret scanning to development and release pipelines to prevent future credential commits.
