T09 · Insecure Skill Coding Practices
- Location
SKILL.md:66- Finding
Insecure Database Credential Storage and TLS Configuration Guidance
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 66–119 and 431–466
Vulnerability Type: Insecure credential handling and transport configuration
Risk Level: MediumVulnerable Code
bash MYSQL_PWD=yourpassword mysql -h 127.0.0.1 -u app_user --database app_db -s -rbash MYSQL_PWD=password mysql -h 192.168.1.100 -P 3306 -u admin --database mydb --ssl-mode=REQUIRED --connect-timeout=10 -s -rini [client] host = 127.0.0.1 port = 3306 user = app_user database = app_db password = yourpassword ssl-mode = DISABLEDbash export MYSQL_PWD="yourpassword" export MYSQL_HOST="127.0.0.1" export MYSQL_USER="app_user" export MYSQL_DATABASE="app_db" mysql -s -r -e "SELECT 1;"The security guidance subsequently recommends the same environment-variable mechanism:
text 2. Use the MYSQL_PWD environment variable or a configuration fileTechnical Analysis
The Skill presents
MYSQL_PWDand a plaintext MySQL option file as preferred credential-handling mechanisms. Passwords stored in environment variables can be inherited by child processes and may be exposed through diagnostic tools, process inspection available to sufficiently privileged local users, crash reports, debugging output, or accidental environment logging. A plaintext option file similarly exposes a reusable database credential if file permissions, backups, or host access are not adequately controlled.The sample option file also sets
ssl-mode = DISABLED. If this configuration is adapted for a non-local connection, MySQL credentials, queries, and returned data may traverse the network without authenticated encryption. The later recommendations to require TLS in production and apply mode600to the option file reduce risk but contradict the insecure examples and do not prevent users or agents from copying them directly.No real password is embedded in the repository—the displayed va ...[truncated 1642 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
ssl-mode = DISABLEDfrom all examples. For remote connections, use--ssl-mode=VERIFY_IDENTITYwith a trusted CA certificate and hostname verification. - Do not describe
MYSQL_PWDas the preferred secure mechanism. Prefer interactive password prompting, an approved secret manager, short-lived credentials, ormysql_config_editor. - If an option file is unavoidable, create it with restrictive permissions before writing credentials, keep it outside shared locations, exclude it from source control and backups where appropriate, and document secure deletion and rotation procedures.
- Use dedicated credentials with the minimum necessary database privileges and limited network origin rules.
- Avoid exporting credentials globally. Pass secrets through a narrowly scoped, protected mechanism and ensure they are not inherited by unrelated child processes.
- Add explicit warnings that sample values must never be replaced with production secrets in shell history, checked-in scripts, logs, or broadly readable files.
- Rotate credentials immediately if they are suspected to have appeared in logs, diagnostics, process environments, or exposed configuration files.
- Remove
