T09 · Insecure Skill Coding Practices
- Location
scripts/capabilities/configure/service.py:26- Finding
AK Signing Credential Is Stored with Ambient Permissions and Exposed Through Standard Output
- Content
View full analysis
Tuple[bool, str]: """Write the AK to a local configuration file.""" try: CONFIG_PATH.parent.mkdir(parents=True, exist_ok=True) with open(CONFIG_PATH, "w", encoding="utf-8") as f: json.dump({"ak": api_key}, f, ensure_ascii=False, indent=2) return True, str(CONFIG_PATH) except Exception: return False, "" ``` The callback server returns the unmasked credential after storing it: ```python def _save_ak(self, ak: str) -> dict: from capabilities.configure.service import validate_ak, configure_ak is_valid, error_msg = validate_ak(ak) if not is_valid: return {"success": False, "error": "AK_INVALID", "error_description": error_msg} success, storage_location = configure_ak(ak) if success: return {"success": True, "ak": ak} return {"success": False, "error": "AK_SAVE_FAILED", "error_description": "AK save failed; check file permissions"} ``` The authorization process then emits the full AK to standard output: ```python if completed and server.success: ak = server.result.get("ak", "") _cleanup_pid() output_json({ "success": True, "markdown": "AK configured successfully", "data": {"ak": ak} }) return 0 ``` ### Technical Analysis The AK contains material from which the Access Key ID and signing secret are derived. It must therefore be handled as a reusable authentication credential. The configuration file is created with ordinary `open(..., "w")` behavior. No explicit `0600` mode is enforced, and the parent directory is not explicitly restricted. The effective permissions depend on ...[truncated 1591 chars]- Remediation
View remediation
