T09 · Insecure Skill Coding Practices
- Location
scripts/github_tracker.py:69- Finding
GitHub Personal Access Token Exposed Through Command-Line Arguments and Plaintext Storage
- Content
View full analysis
/github.json.""" creds_dir = os.path.dirname(CREDENTIALS_PATH) os.makedirs(creds_dir, exist_ok=True) with open(CREDENTIALS_PATH, "w") as f: json.dump({"github_token": token}, f, indent=2) f.write("\n") os.chmod(CREDENTIALS_PATH, 0o600) ``` `scripts/github_tracker.py:406`: ```python s.add_argument("--token", help="GitHub PAT (saved to /github.json)") ``` `SKILL.md:35-42`: ```markdown Pass via `setup --token ` (saved to `/github.json`) or set `GITHUB_TOKEN` env var. ⚠ Token is stored plaintext on disk. For higher security, use the `GITHUB_TOKEN` environment variable instead. ## Setup ``` python3 scripts/github_tracker.py setup --token # list your repos ``` ``` ### Technical Analysis The setup workflow accepts a GitHub personal access token directly through a command-line argument and then stores that token unencrypted in `github.json`. Command-line credentials can be exposed through shell history, process inspection facilities, terminal logs, agent execution logs, or command auditing systems. Persisting the token as JSON creates an additional long-lived secret disclosure surface. The file permission is changed to `0600`, which appropriately limits access by other operating-system users, but it does not protect the token from processes running under the same account, compromised user-level applications, plaintext backups, or accidental copying. The token is transmitted only in an `Authorization` header to the fixed HTTPS origin `https://api.github.com`. Repository names affect only the request path and cannot change t ...[truncated 2013 chars]- Remediation
View remediation
