T09 · Insecure Skill Coding Practices
- Location
SKILL.md:14- Finding
Todoist API Token Stored Without Restrictive File Permissions
- Content
View full analysis
~/.config/todoist/config.json ``` ``` ### Technical Analysis The setup instructions store a long-lived Todoist API token in a plaintext configuration file but do not establish restrictive permissions for either the containing directory or the file. `mkdir -p` applies permissions according to the user's current `umask`, while shell redirection creates `config.json` using similarly inherited permissions. With a permissive or misconfigured `umask`, the directory may be traversable and the configuration file may be readable by other local users or processes. The instructions also do not verify or correct permissions on an existing directory or configuration file. Although the CLI may require a file-based token, the credential should be protected explicitly rather than relying on environment-specific defaults. ### Attack Path 1. A user follows the documented setup procedure and places a valid Todoist API token in `~/.config/todoist/config.json`. 2. The user's `umask` or pre-existing directory permissions result in the directory being traversable and the file being readable by another local account or untrusted process. 3. The attacker reads the token from the configuration file. 4. The attacker uses the stolen token with the Todoist API or a compatible client. 5. The attacker accesses or manipulates Todoist data within the permissions granted to that token. This exploitation path requires local filesystem access through another account, a compromised local process, or an equivalent ability to read files under the user's home directory. ### Impact Assessme ...[truncated 478 chars]- Remediation
View remediation
~/.config/todoist/config.json chmod 600 ~/.config/todoist/config.json ``` Additional hardening measures: - Verify and correct permissions even when the directory or file already exists. - Prefer an operating-system credential store or secret manager if supported by the CLI. - Avoid placing the real token directly in shell commands where it may be retained in shell history. - Do not print, log, or commit the token. - Rotate the token immediately if unauthorized filesystem access or credential exposure is suspected. - Document the expected permissions: `0700` for `~/.config/todoist` and `0600` for `config.json`. ]]>
