T09 · Insecure Skill Coding Practices
- Location
SKILL.md:19- Finding
Administrative Credentials Are Collected Through the Conversation Without Secure Secret Handling
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 19-39 and 83
Vulnerability Type: Plaintext sensitive credential handling
Risk Level: HighVulnerable Code Snippet
markdown ## Step 1 — Identify the Platform & Collect Credentials Start by warmly asking which platform the user is on if they haven't said. Then ask for the credentials needed (listed below per platform). Reassure them: > "These are only used for this session and are never stored anywhere." ### Credential requirements by platform | Platform | What to ask for | |---|---| | **Shopify** | Store URL (e.g. `mystore.myshopify.com`) + Admin API Access Token | | **WooCommerce** | Site URL + Consumer Key + Consumer Secret | | **BigCommerce** | Store Hash + API Access Token | | **Wix** | Site ID + API Key (from Wix Dev Center) | | **PrestaShop** | Store URL + API Key | | **Adobe Commerce / Magento** | Store URL + Admin Token or Integration Access Token | | **Amazon (SP-API)** | Marketplace ID + LWA Client ID + Client Secret + Refresh Token | | **Etsy** | Shop ID + API Key + Access Token (OAuth2) | | **Shopware** | Store URL + API Access Key + API Secret Key |The only additional credential-handling control appears at line 83:
markdown - Never expose raw credentials in your responsesTechnical Analysis
The Skill explicitly directs users to submit high-value ecommerce administrator credentials through the conversational interface. These include administrative access tokens, API secrets, OAuth refresh tokens, and client secrets.
No secure secret-entry mechanism, secret-manager integration, tokenization process, transcript-redaction procedure, logging control, or enforced secret lifetime is defined. The instruction not to expose credentials in responses only reduces accidental output disclosure; it does not prevent secrets from entering conversation history, Agent context, tool-call records, telemetry, or other retained execution data.
The statement that credent ...[truncated 1454 chars]
- Remediation
View remediation
Remediation Suggestions
- Prohibit users from pasting raw credentials into ordinary conversation messages.
- Integrate a dedicated masked secret-input mechanism or external secret manager.
- Pass opaque secret references to tools rather than including credential values in Agent-visible context.
- Define and enforce automatic secret expiration and deletion after the requested operation.
- Redact authorization headers, access tokens, API keys, client secrets, and refresh tokens from all logs and tool traces.
- Replace the unsupported “never stored anywhere” assurance with an accurate explanation of retention and processing boundaries.
- Prefer short-lived OAuth access tokens over persistent administrator tokens or refresh tokens.
- Tell users how to revoke and rotate credentials immediately after use.
- Add automated output and logging filters for known credential formats.
- Separate read-only and write-enabled credential workflows so high-risk credentials are requested only when necessary.
