T09 · Insecure Skill Coding Practices
- Location
scripts/gaode_taxi.py:11- Finding
Hard-Coded Shared Proxy Credential
- Content
View full analysis
Vulnerability Details
File Location:
scripts/gaode_taxi.py, lines 11–12 and 19
Vulnerability Type: Hard-coded reusable credential
Risk Level: MediumVulnerable Code
python PROXY_URL = os.environ.get("GAODE_PROXY_URL", "https://1439498936-bl10af74fl.ap-guangzhou.tencentscf.com") PROXY_TOKEN = os.environ.get("GAODE_PROXY_TOKEN", "tp_8k2mX9vQ4z")The credential is subsequently attached to outbound requests:
python req.add_header("X-Proxy-Token", PROXY_TOKEN)Technical Analysis
The source code contains a reusable proxy token as the default value of
GAODE_PROXY_TOKEN. Anyone with access to the distributed skill package can extract this credential without executing the code.When
GAODE_PROXY_TOKENis not set, every proxy request uses the exposed fallback token. BecauseGAODE_PROXY_URLis independently configurable, an attacker who can control the process environment can redirect requests to an attacker-controlled HTTPS endpoint and receive the token through theX-Proxy-Tokenheader.There is also a configuration mismatch:
SKILL.mddeclaresPROXY_TOKENas the primary environment variable, while the script readsGAODE_PROXY_TOKEN. Deployments following the documentation may therefore continue using the embedded fallback credential.Attack Path
- Obtain or inspect the published skill package.
- Read
scripts/gaode_taxi.pyand extract the fallback proxy token. - Reproduce the script's HTTP request format and submit authenticated requests directly to the configured proxy.
- Abuse any proxy operations and quota authorized by the shared token.
- Alternatively, where control over the execution environment exists, set
GAODE_PROXY_URLto an attacker-controlled endpoint. - Invoke any tool that calls
_post; the script sends the fallback token to that endpoint in theX-Proxy-Tokenheader.
Impact Assessment
The exposed credential may permit unauthorized use of the map proxy and its supported oper ...[truncated 475 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the hard-coded fallback token and require the credential to be supplied through a secure secret-management mechanism.
- Fail closed during startup when the required credential is absent rather than silently using a shared default.
- Rotate and revoke the exposed token because publication in source code must be treated as credential compromise.
- Align the documented environment variable with the implementation, preferably using
GAODE_PROXY_TOKENconsistently. - Issue separate, short-lived, narrowly scoped credentials per deployment or user instead of distributing one shared token.
- Restrict the token server-side by allowed operations, rate limits, quotas, expiration, and other applicable request attributes.
- Validate or pin the proxy destination against an explicit allowlist so environment manipulation cannot redirect the authorization header to an arbitrary host.
- Add automated secret scanning to the release process and block publication when credentials or token-like values are detected.
