T09 · Insecure Skill Coding Practices
- Location
scripts/meituan_travel.py:10- Finding
Hardcoded Proxy Authentication Token
- Content
View full analysis
Vulnerability Details
File Location:
scripts/meituan_travel.py, lines 10–11
Vulnerability Type: Hardcoded reusable credential
Risk Level: HighVulnerable Code
python PROXY_URL = os.environ.get("MEITUAN_PROXY_URL", "https://1439498936-5f2xpfi4t3.ap-guangzhou.tencentscf.com") PROXY_TOKEN = os.environ.get("MEITUAN_PROXY_TOKEN", "tp_8k2mX9vQ4z")The embedded token is subsequently used as an authentication header at lines 17–19:
python req = urllib.request.Request(PROXY_URL, data=body, method="POST") req.add_header("Content-Type", "application/json") req.add_header("X-Proxy-Token", PROXY_TOKEN)Technical Analysis
The source code contains a reusable proxy authentication token as the default value of
MEITUAN_PROXY_TOKEN. Environment-variable override support does not protect the default token because anyone who can download or inspect the Skill package can recover it.This violates secret-management and least-exposure principles. Once distributed in source code, the credential must be considered compromised regardless of whether the repository or package is later updated. An attacker can reproduce the application's authenticated HTTP requests without invoking the Skill through its intended interface.
Attack Path
- Obtain the publicly distributed Skill package or otherwise read
scripts/meituan_travel.py. - Extract the proxy URL and hardcoded token from lines 10–11.
- Construct an HTTP POST request to the disclosed proxy endpoint.
- Add the extracted token using the
X-Proxy-Tokenheader, matching the implementation at line 19. - Submit requests directly to the proxy outside the Skill's intended execution path.
- Repeat or automate requests to consume service resources or abuse any proxy operations authorized by that token.
The exact server-side authorization scope cannot be established from the audited files, so access beyond the proxy capabilities granted t ...[truncated 619 chars]
- Obtain the publicly distributed Skill package or otherwise read
- Remediation
View remediation
Remediation Suggestions
- Immediately revoke and rotate the exposed token, treating it as compromised.
- Remove all default credentials from source code, packaged artifacts, examples, and version-control history.
- Require credentials to be supplied at runtime through an approved secret manager or protected environment variable. Fail closed when no credential is configured.
- Issue separate credentials per deployment or user rather than sharing one package-wide token.
- Prefer short-lived, narrowly scoped credentials and restrict them to only the required proxy operation.
- Apply server-side rate limits, quotas, request validation, and abuse monitoring per credential.
- Review proxy logs for suspicious use of the exposed token and invalidate related sessions or derived credentials where applicable.
- Add automated secret scanning to development and release pipelines to block future credential disclosure.
- Align the documented environment-variable name with the implementation so operators can configure the replacement secret correctly.
