T09 · Insecure Skill Coding Practices
- Location
scripts/compare_models.py:24- Finding
DashScope Credential Passed to an OpenAI Model Client
- Content
View full analysis
Vulnerability Details
File Location:
scripts/compare_models.py, lines 24–27
Vulnerability Type: Cross-provider credential disclosure caused by an incorrect model client configuration
Risk Level: HighVulnerable Code
python return OpenAIChatModel( api_key=os.environ.get("DASHSCOPE_API_KEY", os.environ["OPENAI_API_KEY"]), model_name=model_name, )Technical Analysis
build_model()routes every model whose name does not start withgpt-,o1-, oro3-into this branch. The branch retrievesDASHSCOPE_API_KEYwhen available but still constructs anOpenAIChatModel.No DashScope-specific model adapter or verified DashScope-compatible API endpoint is configured. Consequently, the credential selected for Alibaba Cloud is placed into a client configured for a different provider. When
run_task()invokes the resulting agent, the model client can use that credential in its outbound authentication request.This contradicts the documented purpose of
DASHSCOPE_API_KEYinSKILL.md, where it is described as the credential for Alibaba Cloud models. The issue is a reachable provider-boundary error rather than evidence of intentional credential theft.Attack Path
- The operator configures
DASHSCOPE_API_KEYto compare an Alibaba Cloud model, as supported by the skill documentation. - The skill is invoked with a model name that does not start with
gpt-,o1-, oro3-. build_model()enters the fallback branch and selectsDASHSCOPE_API_KEY.- The key is passed to
OpenAIChatModelwithout a DashScope-specific adapter or endpoint. run_task()calls the agent, causing the incorrectly configured model client to make an authenticated model request.- The DashScope credential may therefore be disclosed to the endpoint used by the OpenAI client rather than remaining within its intended provider boundary.
Impact Assessment
A reusable DashScope API credential ...[truncated 548 chars]
- The operator configures
- Remediation
View remediation
Remediation Suggestions
- Use the AgentScope adapter intended for DashScope or Alibaba Cloud models.
- If an OpenAI-compatible client is required, explicitly configure and validate the official DashScope-compatible API endpoint rather than relying on the OpenAI client's default endpoint.
- Represent each provider with a distinct configuration containing its model-name rules, credential variable, client type, and allowed endpoint.
- Reject unknown model names instead of routing every unrecognized model through a credential-bearing fallback.
- Validate before sending a request that the selected credential belongs to the configured endpoint.
- Add tests that mock outbound client configuration and assert that
DASHSCOPE_API_KEYcan only be associated with an approved DashScope endpoint. - After correcting the configuration, rotate any DashScope key that may already have been used through the affected path.
