T09 · Insecure Skill Coding Practices
- Location
SKILL.md:13- Finding
Plaintext Account Passwords and API Credentials Embedded in the Skill
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 13-39
Vulnerability Type: Hardcoded secrets and plaintext sensitive data
Risk Level: HighVulnerable Code
markdown ### GitHub - **Login URL**: https://github.com/login - **Email**: 155143783@qq.com - **Password**: Ft656618 - **Use Case**: ClawHub skill publishing and repository management ### Zhihu - **Login URL**: https://www.zhihu.com/signin - **Phone Number**: 13308844548 - **Password**: 110827zcm - **Use Case**: BotStreet task delivery ### Xianyu - **Login Method**: Taobao account login - **Account**: 13308844548 - **Password**: ft656618 - **Use Case**: Publishing Xianyu products ### BotStreet - **Platform**: BotStreet.cn - **agentId**: 167441766587305984 - **agentKey**: ak-xv1frJKdz9MmIThDNmSLpVP64X5pwFIurEVUzgMSuxib4Ebf ### Xiaping Skill - **Platform**: https://xiaping.coze.site - **Username**: zaizai-agent - **api_key**: agent-world-1687b6ad18e9faafc50ee074b541dbd478fdbdd689cb2f26Technical Analysis
The Skill embeds multiple account passwords, an agent key, and an API key directly in a document loaded into an Agent's context. These secrets are available to anyone who can read the package, repository, Agent context, generated logs, backups, or distributed copies of the Skill.
This contradicts the document's own assertion that credentials are stored only in
SECRET.md. Because the secrets are plaintext rather than references to scoped secret-manager entries, no additional access-control boundary protects them after the Skill is obtained. The apparent reuse of related password patterns across services may also increase the scope of a credential-stuffing attack.Attack Path
- An attacker obtains read access to the Skill package, repository, Agent context, log output, backup, or published copy.
- The attacker reads the plaintext account passwords and API credentials from
SKILL.md. - Th ...[truncated 1126 chars]
- Remediation
View remediation
Remediation Suggestions
- Immediately revoke and rotate every password, agent key, and API key exposed in the file.
- Review account and API audit logs for unauthorized authentication or activity since the credentials were introduced.
- Remove all secret values from the current file and from repository history, package releases, caches, backups, and published copies where feasible.
- Store credentials in a dedicated secret manager or protected runtime environment rather than in Skill instructions.
- Give the Agent only opaque, service-specific secret references; do not place resolved secret values in the model context.
- Use separate credentials for each service and prohibit password reuse.
- Restrict API credentials to the minimum required scopes, destinations, operations, and expiration period.
- Require explicit user authorization before the Agent authenticates or performs account-changing operations.
- Add automated secret scanning and pre-commit checks to prevent recurrence.
- Configure browser and Agent logging to redact password fields, authorization headers, API keys, cookies, and session tokens.
