T09 · Insecure Skill Coding Practices
- Location
src/service.py:27- Finding
API Credential Transmitted in a URL Query String
- Content
View full analysis
str: """Build the TradingEconomics calendar URL for a date range.""" path = ( f"/calendar/country/{CALENDAR_COUNTRY_SCOPE}/" f"{start_date.isoformat()}/{end_date.isoformat()}" ) query = urlencode({"c": api_key, "f": "json"}) return f"{API_BASE_URL}{path}?{query}" ``` ### Technical Analysis The TradingEconomics API credential is inserted into the `c` URL query parameter. Although the destination is a hard-coded official HTTPS endpoint, query strings are commonly retained in reverse-proxy logs, server access logs, network monitoring products, debugging output, browser or client histories, and application-performance monitoring systems. TLS protects the complete request from passive network observers, but it does not prevent endpoint infrastructure or local instrumentation from recording the URL. Consequently, the credential may be exposed to parties that have access to logs but are not intended to possess API credentials. The outbound request is necessary for the Skill’s declared economic-calendar functionality and is not evidence of covert data exfiltration. However, transmitting a reusable secret in a URL creates more exposure than header-based authentication and does not follow least-disclosure principles. ### Attack Path 1. A user configures `TRADING_ECONOMICS_API_KEY` in the process environment or a loaded `.env` file. 2. `get_economic_calendar()` passes the credential to `fetch_tradingeconomics_payload()`. 3. `build_calendar_url()` embeds the complete credential in the URL query string. 4. The URL is processed by local monitoring infrastructure, an HTTPS proxy, the provider’s edge infrastructure, or provider-side access logging. 5. A party w ...[truncated 626 chars]- Remediation
View remediation
