T09 · Insecure Skill Coding Practices
- Location
scripts/group_tour.py:17- Finding
Hardcoded Shared Proxy Authentication Token
- Content
View full analysis
Vulnerability Details
File Location:
scripts/group_tour.py, lines 15–17 and 74–108
Vulnerability Type: Hardcoded credential
Risk Level: MediumVulnerable Code
python TONGCHENG_PROXY = "https://1439498936-7vqpkiipef.ap-guangzhou.tencentscf.com" FLIGGY_PROXY = "https://1439498936-6sysdjjt99.ap-guangzhou.tencentscf.com" PROXY_TOKEN = os.environ.get("PROXY_TOKEN", "tp_8k2mX9vQ4z")The credential is attached to requests to both proxy services:
python def _call_tongcheng(rtype, params): """调用同程SCF代理""" body = json.dumps( {"type": rtype, "params": params}, ensure_ascii=False, separators=(",", ":"), ).encode("utf-8") req = urllib.request.Request( TONGCHENG_PROXY, data=body, headers={ "Content-Type": "application/json", "X-Proxy-Token": PROXY_TOKEN, }, method="POST", ) try: with urllib.request.urlopen(req, timeout=TC_TIMEOUT) as r: return json.loads(r.read().decode("utf-8"))python def _call_fliggy(rtype, params, timeout=None): """调用飞猪SCF代理""" body = json.dumps( {"type": rtype, "params": params}, ensure_ascii=False, separators=(",", ":"), ).encode("utf-8") req = urllib.request.Request( FLIGGY_PROXY, data=body, headers={ "Content-Type": "application/json", "X-Proxy-Token": PROXY_TOKEN, }, method="POST", ) _timeout = timeout or FG_TIMEOUT try: with urllib.request.urlopen(req, timeout=_timeout) as r: return json.loads(r.read().decode("utf-8"))Technical Analysis
The implementation retrieves
PROXY_TOKENfrom the environment but supplies a static fallback value embedded in the distributed source code. Anyone able to obtain the Skill package can recove ...[truncated 2164 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the hardcoded fallback value and require the credential to be provided securely at runtime:
python PROXY_TOKEN = os.environ.get("PROXY_TOKEN") if not PROXY_TOKEN: raise RuntimeError("PROXY_TOKEN is required") - Immediately revoke and rotate the exposed token, because removing it from a future release does not invalidate copies already distributed.
- Store replacement credentials in the platform's secret-management facility rather than source code, package metadata, logs, or command-line arguments.
- Use separate credentials for the Tongcheng and Fliggy proxies to reduce the impact of a single credential disclosure.
- Restrict each credential server-side to the minimum required request types and upstream operations.
- Validate request schemas and reject unknown
typevalues or unexpected parameters at the proxy boundary. - Apply per-client rate limits, quotas, expiration, rotation, anomaly monitoring, and audit logging.
- Where the hosting platform supports it, bind access to trusted workload identity or signed short-lived requests rather than a reusable shared token.
- Ensure proxy logs redact authentication headers and apply a documented retention policy to travel-search data.
- Remove the hardcoded fallback value and require the credential to be provided securely at runtime:
