T09 · Insecure Skill Coding Practices
- Location
scripts/compare.py:24- Finding
Hard-Coded Proxy Authentication Token
- Content
View full analysis
Vulnerability Details
File Location:
scripts/compare.py, lines 24-34 and 397-402
Vulnerability Type: Hard-coded credential exposure
Risk Level: HighVulnerable Code
python PROXY_TOKEN = os.environ.get("PROXY_TOKEN", "tp_8k2mX9vQ4z") SCF_FLIGGY_URL = "https://1439498936-6sysdjjt99.ap-guangzhou.tencentscf.com" SCF_TUNIU_URL = "https://1439498936-0junm3maxj.ap-guangzhou.tencentscf.com" SCF_RG_URL = "https://1439498936-460a7b6oqn.ap-guangzhou.tencentscf.com" SCF_HOTEL_URL = "https://1439498936-4wdncmn2oj.ap-guangzhou.tencentscf.com" HEADERS = { "Content-Type": "application/json", "X-Proxy-Token": PROXY_TOKEN, }The token is attached to outbound requests as follows:
python data = json.dumps(body, ensure_ascii=False).encode("utf-8") req = urllib.request.Request(url, data=data, headers=HEADERS, method="POST") try: with urllib.request.urlopen(req, timeout=timeout) as r: return json.loads(r.read().decode("utf-8"))Technical Analysis
The script embeds a proxy authentication token as the fallback value when the
PROXY_TOKENenvironment variable is absent. Because the project package is distributed to users, this value must be treated as publicly exposed rather than secret.The same credential is sent in the
X-Proxy-Tokenheader to four publicly reachable Tencent SCF endpoints. An attacker who obtains the package can extract the token without executing the Skill and replay it independently of the intended client. The effective scope depends on server-side authorization, validation, and rate limiting, which are not present in the audited repository and therefore cannot be verified.Using an environment-variable override does not mitigate the exposure because the embedded fallback remains active in default installations.
Attack Path
- Download or otherwise obtain the publicly distributed Skill package.
- Inspect
scripts/compare.pyand extract the defaultPROXY_TOKENvalue and SCF endpoint URL ...[truncated 1236 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke and rotate the exposed token immediately. Assume it has already been copied from every published version containing it.
- Remove the fallback credential from source code. Fail closed when no credential is configured:
python PROXY_TOKEN = os.environ.get("PROXY_TOKEN") if not PROXY_TOKEN: raise RuntimeError("PROXY_TOKEN must be configured securely") - Provide credentials through an approved secret manager or protected runtime injection mechanism rather than package files, source control, command-line arguments, or logs.
- Issue short-lived, per-user or per-installation credentials instead of one shared static token. Support revocation and automatic rotation.
- Apply server-side least privilege. Allow only the request types and upstream APIs required by this Skill, and reject unknown operations and parameters.
- Enforce rate limits and quotas per identity, user, and source to reduce cost and denial-of-service exposure.
- Validate all proxy requests server-side rather than treating possession of the shared header value as sufficient authorization.
- Monitor for abuse of the exposed token and review historical logs for unusual request volume, unsupported operation types, or unexpected source addresses.
- Add automated secret scanning to source-control and release pipelines to prevent credentials from being republished.
