T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:45- Finding
API Key Persisted in a Plaintext File Without Restrictive Permissions
- Content
View full analysis
bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return True ``` ### Technical Analysis The function writes the supplied API key directly to `.env` as plaintext. `Path.write_text()` creates or overwrites the file using permissions derived from the process umask, but the code does not explicitly enforce owner-only permissions such as `0600`. If `.env` already exists with permissive permissions, rewriting it does not correct those permissions. If it is newly created under a permissive umask, other local users or processes may be able to read the credential. The secret also remains on disk across sessions until manually removed. The API key is subsequently used as the `XBY-APIKEY` authentication header when communicating with the configured upstream service. Disclosure can therefore allow an attacker to impersonate the affected API client. ### Attack Path 1. A user supplies an API key as required by the skill workflow. 2. `set_api_key()` invokes `save_api_key_to_env()`. 3. The function stores the key in the project working directory as `XBY_APIKEY=<secret>`. 4. The code do ...[truncated 988 chars]- Remediation
View remediation
