T09 · Insecure Skill Coding Practices
- Location
scripts/astock_api.py:8- Finding
Hardcoded Undocumented API Token Transmitted in URL Query Parameters
- Content
View full analysis
3 else DEFAULT_TOKEN result = call_api(endpoint, code, token) ``` The implementation's `admin_mllx_2026` default differs from the documented trial token, `trial_free_2026`, in `SKILL.md:42-50`. ### Technical Analysis The script embeds an undocumented API credential directly in source code and uses it automatically. Anyone who can obtain the Skill package can recover and reuse the credential. Its name suggests that it might have administrative or otherwise elevated scope, although its actual server-side privileges cannot be verified through static analysis. The token—whether the embedded default or a private token supplied by the user—is interpolated into the URL query string. Query strings are frequently retained in web-server access logs, reverse-proxy logs, monitoring systems, diagnostics, and command histories. TLS protects the URL while it is in transit but does not prevent the client, destination server, or authorized intermediaries from recording it. Authentication to the declared stock-data API is necessary for the Skill's functionality, so the outbound reques ...[truncated 1495 chars]- Remediation
View remediation
