T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:42- Finding
API Key Stored Persistently in a Plaintext Environment File
- Content
View full analysis
bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return True except Exception as e: print(f"保存API key失败: {e}") return False ``` ### Technical Analysis The application persistently writes the user-supplied API key to a plaintext `.env` file. It does not explicitly apply restrictive file permissions, use an operating-system credential store, reject symbolic links, or create the file atomically. When the file already exists, its current permissions are retained. When it is created, its effective permissions depend on the process umask. Consequently, the credential may be readable by other local users or processes. Plaintext environment files are also commonly exposed through repository commits, backups, support archives, or broad project-directory access. The direct assignment to `os.environ` additionally makes the credential available to subsequently launched child processes. ### Attack Path 1. A user supplies an API key as instructed by the Skill. 2. `set_api_key()` calls `save_api_key_to_env()`. 3. The key is written as `XBY_APIKEY=` in the project’s `.env` file. 4. An attacker with access to t ...[truncated 759 chars]- Remediation
View remediation
