T09 · Insecure Skill Coding Practices
- Location
scripts/humanize.py:28- Finding
Hard-Coded Bearer Token Exposes Dashboard API Credentials
- Content
View full analysis
Tuple[Optional[str], Optional[str]]: """Return (token, source)""" token = os.getenv("DASHBOARD_TOKEN") or DEFAULT_TOKEN if token: return token, "env:DASHBOARD_TOKEN" ``` ### Technical Analysis The source code contains a bearer token that appears intended to authenticate requests to the Dashboard API. Every person or system with access to the Skill package can extract and reuse this token independently of the script. Because `_get_token()` selects the environment token or the hard-coded default before considering phone/password login, the embedded credential is used automatically whenever `DASHBOARD_TOKEN` is absent. The default token also makes the subsequent login fallback unreachable under the distributed configuration. Bearer tokens confer access based on possession. There is no additional proof that the caller is an authorized installation or user. ### Attack Path 1. An attacker downloads or otherwise obtains access to the Skill package. 2. The attacker opens `scripts/humanize.py` and extracts `DEFAULT_TOKEN`. 3. The attacker constructs requests with an `Authorization: Bearer ` header. 4. The attacker sends requests directly to the Dashboard API outside the intended Skill workflow. 5. The API processes those requests under the identity and authorization scope associated with the embedded token, provided it remains valid. ### Impact Assessment An attacker may obtain all API privileges assigned to the exposed token. Depending on server-side authorization, this can include unauthorized use of the humanization service, consumption of quotas or paid resources, activity attribution to the token owner, and access t ...[truncated 276 chars]- Remediation
View remediation
