T09 · Insecure Skill Coding Practices
- Location
references/jsapigl/demos/个性化地图_切换地图个性化样式.html:10- Finding
Hardcoded Tencent Maps API Key in Bundled Documentation and Executable Demos
- Content
View full analysis
``` Other confirmed usage patterns include direct inclusion in service requests: ```javascript url += "&key=OB4BZ-D4W3U-B7VVO-4PJWW-6TKDJ-WPB77"; // Development key ``` ```javascript url: "https://apis.map.qq.com/ws/district/v1/getchildren?key=OB4BZ-D4W3U-B7VVO-4PJWW-6TKDJ-WPB77&output=jsonp&get_polygon=2&max_offset=3000" ``` ### Technical Analysis A Tencent Maps API key is embedded directly in executable HTML examples and documentation. This conflicts with the Skill configuration in `SKILL.md`, which declares `TMAP_JSAPI_KEY` as the required environment variable and recommends using `{TMAP_JSAPI_KEY}` in generated code. Although browser-facing map keys are necessarily transmitted to clients, they should still be restricted to authorized domains, APIs, and quotas. Committing a concrete reusable key to the package makes it immediately discoverable and encourages users or Agents to copy it into generated applications. The key is also placed directly in web-service request URLs in some examples. The audit did not verify whether the key rem ...[truncated 1723 chars]- Remediation
View remediation
``` 3. **Enforce server-side key restrictions** - Restrict browser keys to explicitly authorized referrer domains. - Enable only the Tencent Maps APIs required by the application. - Apply suitable request quotas and billing alerts. - Use separate keys for development, demonstration, testing, and production. 4. **Prevent generated-code propagation** - Amend the Skill instructions to explicitly prohibit copying credentials from reference demos. - Require generated examples to use placeholders or configuration injection. - Clearly state that users must create and restrict their own Tencent Maps key. 5. **Add automated secret detection** - Run secret scanning in pre-commit hooks and continuous integration. - Include patterns for Tencent Maps key formats and credentials embedded in URL query strings. - Fail builds when concrete API keys are found in documentation, source code, or demo assets. 6. **Verify remediation comprehensively** - Search the entire repository for the exposed key after replacement. - Confirm that no historical build artifacts or packaged releases still contain it. - Rotate the credential even after removal because repository deletion does not invalidate previously distributed copies ...[truncated 7 chars]
