T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:43- Finding
API Key Persisted in a Plaintext File Without Secure File Controls
- Content
View full analysis
Vulnerability Details
File Location:
scripts/config.py:43-64
Vulnerability Type: Plaintext credential storage and unsafe file handling
Risk Level: Mediumpython env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return TrueTechnical Analysis
The supplied API key is stored in plaintext in a working-directory-relative
.envfile. The implementation does not create the file with restrictive permissions, validate existing permissions, reject symbolic links, or perform an atomic write.Because
Path(".env")is resolved relative to the process working directory, the destination may differ depending on how the Skill is launched. If an attacker can prepare that directory, an existing.envsymbolic link can redirect the credential write to another file writable by the Skill process.The credential is also copied into the process environment, making it accessible to code running within the same process and potentially to child processes created later.
Attack Path
- An attacker obtains read access to the working directory or prepares a malicious
.envsymbolic link before Skill execution. - The Skill asks the user for an
XBY_APIKEY. set_api_key()invokes the persistence logic.- The key is written in plaintext without restrictive permission enforcement, or the symbolic link redirects the write.
- The attacker reads the key from the resulting file or causes an unintended file to be overwritten within the process's existing filesystem p ...[truncated 377 chars]
- An attacker obtains read access to the working directory or prepares a malicious
- Remediation
View remediation
Remediation Suggestions
- Prefer session-only credential handling or an operating-system credential manager rather than plaintext persistence.
- Obtain explicit user consent before persisting a credential.
- Resolve the credential file against a fixed, trusted application directory instead of the current working directory.
- Reject symbolic links and verify that any existing destination is a regular file owned by the expected user.
- Create the file atomically with owner-only permissions, such as mode
0600. - Avoid copying the key into the process environment unless required.
- Ensure
.envis excluded from source control, backups, logs, and diagnostic bundles. - Support credential rotation and deletion.
