T09 · Insecure Skill Coding Practices
- Location
SKILL.md:85- Finding
Recursive Credential Search Exposes Cloudflare Secrets in Plaintext
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 85–88
Vulnerability Type: Plaintext sensitive-data exposure during credential discovery
Risk Level: MediumVulnerable Code
markdown Read `CF_OBSERVABILITY_ACCOUNT_ID` and `CF_OBSERVABILITY_API_TOKEN` from environment variables. If not set in the shell, search for them in project `.env` files: ```bash grep -r 'CF_OBSERVABILITY_' --include='.env' --include='.env.*' . 2>/dev/nulltext ### Technical Analysis When credentials are unavailable in the shell environment, the Skill instructs the agent to recursively search the current directory and print every matching line from `.env` and `.env.*` files. Because `grep` writes the complete matching lines to standard output, values such as `CF_OBSERVABILITY_API_TOKEN` are exposed in plaintext. This output may be retained in the agent's context, command transcript, terminal scrollback, execution logs, or other telemetry. The recursive search also crosses nested directories, so it can discover credentials belonging to unrelated projects beneath the working directory. Access to a credential is necessary to query Cloudflare, but recursively printing secret-bearing configuration is not necessary. The behavior therefore exceeds the minimum access needed for credential loading. The intended network request to the official `https://api.cloudflare.com` endpoint is consistent with the declared functionality; no evidence of transmission to an unrelated third party was found. ### Attack Path 1. A user invokes the Skill while the required Cloudflare variables are not exported in the shell. 2. The agent follows the fallback instruction and runs the recursive `grep` command from the project directory. 3. The command locates one or more `.env` files, potentially including files in nested or unrelated projects. 4. Complete matching assignments, including the Cloudflare bearer token, are printed to command output. 5. The exposed token is incorporated i ...[truncated 1026 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the recursive command that prints secret-bearing lines.
- Require credentials to be supplied through the process environment or a secret manager whenever possible.
- If
.envfallback is retained, load a single explicitly selected file without echoing its contents. Do not recursively search nested directories. - Ask for user confirmation before reading a credential file that was not explicitly configured.
- Suppress and redact secret values in all command output, diagnostics, errors, and agent responses. Display only whether a variable was found.
- Avoid placing the bearer token directly in visible shell command text where execution tooling may log it. Use a protected configuration file, secure environment injection, or a secret-aware request mechanism.
- Recommend a dedicated token restricted to the intended Cloudflare account and the narrowest permission accepted by the API. Document the security implications if Cloudflare requires an
Editpermission for query operations. - Advise users to exclude
.envfiles from version control, restrict their filesystem permissions, rotate any token exposed in prior transcripts, and review Cloudflare audit activity for unauthorized use.
