T09 · Insecure Skill Coding Practices
- Location
source/proxy_manager.py:54- Finding
Proxy credentials are exposed through command-line arguments, plaintext storage, and unredacted output
- Content
View full analysis
Vulnerability Details
File Location:
source/proxy_manager.py:54-56,source/proxy_manager.py:95-97,source/proxy_manager.py:188-203,source/proxy_manager.py:220-228, andsource/proxy_manager.py:338-339
Vulnerability Type: Plaintext sensitive-data storage and credential disclosure
Risk Level: MediumVulnerable Code
Plaintext configuration storage at
source/proxy_manager.py:54-56:python CONFIG_DIR.mkdir(parents=True, exist_ok=True) with open(CONFIG_FILE, "w", encoding="utf-8") as f: json.dump(config, f, indent=2, ensure_ascii=False)Credentials embedded in proxy URLs at
source/proxy_manager.py:95-97:python if proxy.get("username") and proxy.get("password"): proxy_url += f"{proxy['username']}:{proxy['password']}@" proxy_url += f"{proxy['host']}:{proxy['port']}"Unredacted account-proxy output at
source/proxy_manager.py:188-203:python proxy_url = f"{proxy['protocol']}://" if proxy.get("username") and proxy.get("password"): proxy_url += f"{proxy['username']}:{proxy['password']}@" proxy_url += f"{proxy['host']}:{proxy['port']}" print(f"📦 账号 {account_id} 的代理配置:") print(f" HTTP_PROXY={proxy_url}") print(f" HTTPS_PROXY={proxy_url}") print() print("💻 Python requests 用法:") print(f" proxies = {{'http': '{proxy_url}', 'https': '{proxy_url}'}}") print(f" response = requests.get(url, proxies=proxies)") print() print("🐘 curl 用法:") print(f" curl -x '{proxy_url}' https://example.com")Unredacted random-proxy output at
source/proxy_manager.py:220-228:python proxy_url = f"{proxy['protocol']}://" if proxy.get("username") and proxy.get("password"): proxy_url += f"{proxy['username']}:{proxy['password']}@" proxy_url += f"{proxy['host']}:{proxy['port']}" print(f"🎲 随机代理:{proxy.get('name', proxy.get('id', ''))}") print(f" HTTP_PROXY={proxy_url}") print(f" HTTPS_PROXY={proxy_url}")Password ...[truncated 2626 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove or deprecate the
--passwordcommand-line option. Prompt interactively with Python'sgetpass.getpass()or retrieve the password from a dedicated secret manager. - If noninteractive operation is required, accept a reference to a protected secret rather than the secret itself. Avoid ordinary environment variables where stronger secret-injection mechanisms are available.
- Create the configuration file atomically with owner-only mode
0600, and ensure the configuration directory is not accessible to unrelated users. - Check permissions on existing configuration files at startup. Refuse to use insecurely permissioned files or warn the operator and correct their mode.
- Do not print authenticated proxy URLs by default. Redact passwords, for example by displaying
username:******@host:port. - Provide an explicit, security-gated export operation only when a caller genuinely requires the complete URL. Document that its output must not be logged.
- Separate nonsensitive proxy metadata from credentials. Store only a credential reference in
proxies.json, with the actual password held in an operating-system keyring or secret manager. - Review and rotate existing proxy credentials because they may already exist in shell histories, configuration files, or captured command output.
- Update documentation and examples so they do not encourage passing passwords on the command line or printing authenticated URLs.
- Remove or deprecate the
