T09 · Insecure Skill Coding Practices
- Location
scripts/shanghai_disney.py:14- Finding
Hardcoded Proxy Authentication Token
- Content
View full analysis
Vulnerability Details
File Location:
scripts/shanghai_disney.py, lines 14–15 and 101–107
Vulnerability Type: Hardcoded secret in distributable source code
Risk Level: MediumVulnerable Code
python GAODE_PROXY_URL = "https://1439498936-bl10af74fl.ap-guangzhou.tencentscf.com" GAODE_PROXY_TOKEN = os.environ.get("PROXY_TOKEN", "tp_8k2mX9vQ4z")The embedded credential is subsequently sent as an authentication header:
python def _call_gaode_proxy(api_type, params): body = json.dumps( {"type": api_type, "params": params}, ensure_ascii=False, separators=(",", ":") ).encode("utf-8") req = urllib.request.Request(GAODE_PROXY_URL, data=body, method="POST") req.add_header("Content-Type", "application/json") req.add_header("X-Proxy-Token", GAODE_PROXY_TOKEN) try: with urllib.request.urlopen(req, timeout=15) as resp: data = json.loads(resp.read().decode("utf-8"))Technical Analysis
The script uses an environment variable when available but falls back to a static proxy authentication token embedded directly in the distributed source. Because every recipient of the Skill can inspect the script, the fallback value cannot be treated as confidential.
An attacker can extract both the fixed Tencent Cloud Function endpoint and the token, then issue requests independently of the Skill. The exact operations exposed depend on the proxy's server-side authorization and request validation, which are not included in the audited project. The confirmed exposure therefore enables credential reuse; broader proxy compromise cannot be established from the available code.
Attack Path
- Download or inspect the published Skill package.
- Open
scripts/shanghai_disney.py. - Extract the proxy endpoint from line 14 and the fallback token from line 15.
- Construct an HTTPS POST request to the endpoint.
- Place the extracted value in the
X-Proxy-Tokenheader. - Submit requests ...[truncated 636 chars]
- Remediation
View remediation
Remediation Suggestions
- Immediately revoke and rotate the exposed proxy token.
- Remove the hardcoded fallback and fail safely when
PROXY_TOKENis absent:
python GAODE_PROXY_TOKEN = os.environ.get("PROXY_TOKEN") if not GAODE_PROXY_TOKEN: raise RuntimeError("PROXY_TOKEN is required")- Inject the token through the runtime's approved secret-management mechanism rather than source code, package metadata, logs, or command-line arguments.
- Prefer short-lived, narrowly scoped credentials over a permanent shared token.
- Enforce server-side authorization for every supported proxy operation; do not rely solely on possession of one static header.
- Apply strict allowlisting and schema validation to the proxy's
typeandparamsfields. - Add per-client rate limits, quotas, anomaly detection, and credential-reuse monitoring.
- Avoid logging authentication headers and redact secrets from diagnostic output.
- Review access logs for unauthorized use of the exposed token before rotation.
- Add automated secret scanning to the release pipeline to prevent future credential publication.
