T09 · Insecure Skill Coding Practices
- Location
SKILL.md:124- Finding
Plaintext API Key Persistence in the Skill Definition
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 124-128
Vulnerability Type: Plaintext credential storage
Risk Level: MediumVulnerable Code
markdown 1. **Check key before API calls**: Verify that X-Square-OpenAPI-Key is configured and not the placeholder `your_api_key` 2. **Prompt for key if missing**: If key is not configured, ask user to provide their API Key first 3. **Prompt for content if missing**: If user triggers posting but doesn't provide specific content, ask what they want to post 4. **Never display full keys**: Only show first 5 + last 4 characters (e.g., `abc12...xyz9`) 5. **Store provided keys**: When user provides a new key, update the Accounts section in this fileThe corresponding documentation in
README.md, lines 50-56, andREADME.cn.md, lines 50-56, states that the key will be stored securely for future use, although no secure storage mechanism is defined.Technical Analysis
The skill directs the agent to request an API key through the conversation and persist it by updating
SKILL.md. This stores a sensitive credential in a plaintext project instruction file rather than an operating-system keychain, credential vault, or approved secret manager.Masking a key when displaying it does not protect the plaintext value at rest. The project directory may be included in source-control commits, archives, backups, diagnostic bundles, or future agent context. The instruction also references an “Accounts section” that is absent from the reviewed file, leaving the storage format and access controls undefined.
The README claim that the key is stored securely is inconsistent with the implemented instruction and may cause users to provide credentials without understanding the storage risk.
Attack Path
- A user invokes the Square posting skill without a configured API key.
- The agent requests the user's
X-Square-OpenAPI-Key. - The user submits the credential ...[truncated 1415 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to write API keys into
SKILL.mdor any other project file. - Store credentials in an operating-system keychain, an approved secret manager, or a platform-provided encrypted credential store.
- If environment variables are supported, store only the variable name in skill configuration and retrieve its value at runtime.
- Prevent secret values from appearing in conversation transcripts, application logs, telemetry, error messages, source-control history, and generated artifacts.
- Define an explicit account configuration schema that stores only non-sensitive metadata, such as account aliases and descriptions.
- Enforce least-privilege credentials dedicated exclusively to Binance Square posting where supported.
- Update both README files to accurately describe the credential-storage mechanism and provide key rotation and revocation instructions.
- If keys have already been written into project files, remove them from current files and repository history, rotate them immediately, and review account activity for unauthorized use.
- Remove the instruction to write API keys into
