T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:45- Finding
API Key Persisted in a Plaintext File Without Enforced Access Restrictions
- Content
View full analysis
bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return True except Exception as e: print(f"保存API key失败: {e}") return False ``` ### Technical Analysis The function stores the user-supplied API key directly in a plaintext `.env` file. The call to `Path.write_text()` does not explicitly create the file with restrictive permissions or correct the permissions of an existing file. For a newly created file, its effective permissions depend on the process umask. For an existing `.env` file, any previously permissive access mode remains in effect. Consequently, the credential may become readable by other local accounts or processes that can access the project directory. Plaintext storage also makes the key susceptible to disclosure through source-control commits, directory archives, workspace synchronization, and backup systems. The key is additionally copied into the process environment. Although required for the current design, this increases exposure to processes or diagnostic facilities that are permitted to inspect that environment. ### Attack Path 1. A user supplies a valid Xiaobenyang API key to ...[truncated 1156 chars]- Remediation
View remediation
