T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:46- Finding
API Key Persisted in an Insecure Plaintext File
- Content
View full analysis
bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return True ``` ### Technical Analysis The function stores the API key as plaintext in a `.env` file relative to the process's current working directory. `Path.write_text()` uses ordinary filesystem permissions and does not ensure that the resulting file is accessible only to the current user. The implementation also performs no check that `.env` is a regular file rather than a symbolic link. If an attacker can prepare the working directory, a pre-created `.env` symbolic link may redirect the write to another file writable by the victim. Existing `.env` permissions are also preserved without validation. The credential is additionally copied into the process environment. Child processes started afterward could inherit it, although this project does not itself start child processes. ### Attack Path 1. An attacker obtains access to the directory from which the Skill will run, or the Skill is launched from an attacker-influenced working directory. 2. The attacker creates a permissive `.env` file or a `.env` symbolic link to another victim-writable file. 3. The us ...[truncated 943 chars]- Remediation
View remediation
