T09 · Insecure Skill Coding Practices
- Location
scripts/exchange_link_builder.py:165- Finding
Live Vipshop Access Token Exposed in Generated Product URL
- Content
View full analysis
, ts={timestamp}") # Convert to JSON string json_str = json.dumps(data_obj, separators=(",", ":")) log(f"JSON string: {json_str[:50]}... (length: {len(json_str)})") # Base64 encode base64_str = base64.b64encode(json_str.encode("utf-8")).decode("utf-8") log(f"Base64 result: {base64_str[:50]}... (length: {len(base64_str)})") # Generate signature signature = _generate_signature(base64_str, secret) log(f"Generated signature: {signature[:20]}... (length: {len(signature)})") # Construct complete link base_url = "https://passport.vip.com/exchangeTokenFromApp" full_url = ( f"{base_url}?" f"dt={urllib.parse.quote(base64_str)}&" f"sg={signature}&" f"src={urllib.parse.quote(target_url)}" ) ``` The resulting credential-bearing URL is placed in the command output: ```python # 8. Link: generate linked-login URL containing an exchange token brand_id = base.get("brandId", "") if brand_id and product_id: result["链接"] = build_product_link(brand_id, product_id) ``` The signing secret is also embedded directly in the source at `scripts/exchange_link_builder.py:39-46`: ```python def _get_secret() -> str: """ Get secret key Returns: Secret key string """ return "5fb86e55b72bfc50f083049130e5e76a75c2cbda6bbd6e51d59668057f5c1715" ``` ### Technical Analysis The value placed in the `dt` query parameter is a Base64 encoding of a JSON object containing the live `PASSPORT_ACCESS_TOKEN`. Base64 provides no confidentiality: any recipient can URL-decode and Base64-decode the parameter without k ...[truncated 2305 chars]- Remediation
View remediation
str: return ( f"https://detail.vip.com/" f"detail-{brand_id}-{product_id}.html?pcf=AIClaw" ) ``` 2. Do not print, serialize, log, or otherwise return `PASSPORT_ACCESS_TOKEN`. 3. If authenticated link exchange is essential, use a server-generated, narrowly scoped, single-use code that: - Cannot be decoded into the underlying account credential - Expires within a very short period - Is restricted to the intended destination - Cannot be reused for unrelated authenticated operations 4. Remove the hardcoded signing secret. Store secrets in an appropriate secret-management system and rotate the disclosed value. 5. Revoke or rotate access tokens that may already have appeared in generated links or transcripts. 6. Update `SKILL.md` so the Agent never displays URLs containing authentication credentials. 7. Add automated tests that decode every generated query parameter and fail if access tokens, cookies, or other secrets are recoverable. 8. Redact sensitive query parameters from application, proxy, browser, and Agent logs. ]]>
