T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:41- Finding
API Key Persisted in a Plaintext Environment File
- Content
View full analysis
bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return True except Exception as e: print(f"保存API key失败: {e}") return False ``` ### Technical Analysis The function stores the user-supplied API key directly in a plaintext `.env` file in the process's current working directory. It does not explicitly establish restrictive file permissions, use an operating-system credential manager, or verify that the file is excluded from source control and artifact collection. The resulting permissions depend on the current process umask and the permissions of any existing `.env` file. If these controls are permissive, another local account or process may be able to read the credential. Plaintext persistence also makes the key vulnerable to accidental source-control commits, workspace archives, backups, and diagnostic artifact collection. ### Attack Path 1. A user supplies an API key as required by the Skill workflow. 2. `set_api_key()` invokes `save_api_key_to_env()`. 3. The function writes `XBY_APIKEY=` to the current working directory's `.env` file. 4. An actor with access to the workspace, backup, repositor ...[truncated 652 chars]- Remediation
View remediation
