T09 · Insecure Skill Coding Practices
- Location
scripts/core/api/meida/chunks.py:117- Finding
Authentication credentials are exposed through command output and HTTP logging
- Content
View full analysis
>> {method.upper()} {url} {headers} {body}") response = requests.request( method=method.upper(), url=url, headers=headers, data=body, timeout=30 ) logging.info(f"<<< {response.headers} {response.text}") ``` ```python headers["Authorization"] = f"Bearer {self.token}" ... logging.info(f">>> {method.upper()} {url} {headers} {body}") response = requests.request( method=method.upper(), url=url, headers=headers, data=body, timeout=30 ) logging.info(f"<<< {response.headers} {response.text}") ``` ### Technical Analysis The skill instructions explicitly require printing all supported authentication secrets, including the bearer API key and the long-term secret access key. This unnecessarily places credentials in command output, which may be retained in agent transcripts, execution telemetry, shell history, or orchestration logs. The HTTP clients also serialize the complete request header mapping into application logs. For bearer authentication, this records the reusable token verbatim. For AK/SK authentication, the log contains the access-key identifier and a valid request signature. Although a signature is less reusable than the secret key itself, recording signed requests still expands the exposure sur ...[truncated 1613 chars]- Remediation
View remediation
