T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:45- Finding
API Key Persisted in a Plaintext File Without Enforced Restrictive Permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/config.py:45-68
Vulnerability Type: Plaintext credential storage with insufficient file-permission controls
Risk Level: MediumVulnerable Code
python def save_api_key_to_env(api_key: str) -> bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return True except Exception as e: print(f"保存API key失败: {e}") return FalseTechnical Analysis
The function persists the supplied API key as plaintext in a
.envfile located relative to the process's current working directory.Path.write_text()does not explicitly enforce owner-only permissions such as mode0600; the resulting permissions depend on the process umask and any pre-existing file permissions.The use of a current-working-directory-relative path also creates uncertainty about where the secret is stored. The file could be created in a shared workspace, included in backups, or accidentally committed to source control. An existing
.envfile is overwritten without validating its ownership, permissions, or whether it is a symbolic link.Persisting the credential is part of the documented workflow, but permanent plaintext storage is not the minimum privilege necessary to make authenticated API requests. Environment-only or secret-manager-backed storag ...[truncated 1080 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer obtaining the key from a process environment variable or operating-system secret manager without writing it to disk.
- If persistence is essential, use a dedicated user-specific configuration directory rather than the current working directory.
- Create the secret file atomically with owner-only mode
0600, and verify its ownership and permissions before reading or replacing it. - Refuse to write through symbolic links and reject paths that are not regular files.
- Add
.envto.gitignoreand exclude it from archives, logs, diagnostics, and backups where practical. - Avoid printing the key or including it in exception payloads.
- Document the storage location, retention behavior, third-party recipient, and a procedure for deleting or rotating the credential.
