T09 · Insecure Skill Coding Practices
- Location
scripts/generate_auth_token.py:27- Finding
Reusable API credentials are exposed through standard output
- Content
View full analysis
") sys.exit(1) app_key = sys.argv[1] app_secret = sys.argv[2] token = generate_access_token(app_key, app_secret) print(f"Access Token: {token}") print(f"\nUse in Authorization header as: Basic {token}") ``` ### Technical Analysis The generated value is an HTTP Basic authentication credential consisting of `base64(app_key:app_secret)`. Base64 is reversible encoding rather than encryption, hashing, or tokenization. Anyone who obtains the printed value can either decode the original application key and secret or replay the value directly as an HTTP `Authorization: Basic ...` header. Constructing this value in memory is necessary for the API's declared authentication scheme. Printing the complete credential is not necessary for text-to-video generation and exceeds the minimum exposure required by the Skill. This is particularly unsafe in an Agent environment because stdout may be included in tool responses, conversation transcripts, execution logs, telemetry, or retained job output. The same command also takes the secret from `sys.argv`, creating an additional exposure through process inspection. The primary vulnerability at this location, however, is the deliberate emission of the reusable credential to stdout. ### Attack Path 1. A user or Agent follows the documented authentication workflow and invokes the token generator with valid API credentials. 2. The script constructs the reversible Basic authentication value. 3. The complete reusable credential is pr ...[truncated 1047 chars]- Remediation
View remediation
