T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:45- Finding
API Key Persisted in a Plaintext File Without Enforced Access Controls
- Content
View full analysis
Vulnerability Details
File Location:
scripts/config.py, lines 45-67
Vulnerability Type: Plaintext sensitive-data storage
Risk Level: MediumVulnerable Code
python def save_api_key_to_env(api_key: str) -> bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return True except Exception as e: print(f"保存API key失败: {e}") return FalseTechnical Analysis
The function persistently writes the user-supplied API key to a plaintext
.envfile. It does not explicitly enforce owner-only permissions, use a protected credential store, or validate that the destination is a regular file at a trusted location. The relativePath(".env")destination also depends on the process working directory.Consequently, the file's effective permissions depend on the process umask, existing file permissions, and working-directory protections. In a shared or improperly configured environment, another local user or process may be able to read the credential. Persisting the same secret in
os.environadditionally makes it available to code running inside the process and potentially to subsequently launched child processes.The API key is legitimately transmitted in the
XBY-APIKEYheader to the configured HTTPS service inscripts/call_api.py; that network transmission is ne ...[truncated 1512 chars]- Remediation
View remediation
Remediation Suggestions
- Prefer session-only credential handling or an operating-system credential store instead of writing the key to the project directory.
- If file persistence is necessary, use a fixed, user-specific configuration directory rather than a working-directory-relative path.
- Create the credential file atomically with owner-only permissions such as
0600, and verify or correct permissions when updating an existing file. - Refuse symbolic links and verify that the destination is a regular file owned by the expected user before reading or writing it.
- Avoid propagating the secret through environment variables unless required, particularly when the process may launch child processes.
- Ensure
.envis excluded from source control, build artifacts, logs, backups, and shared workspace exports. - Never include the API key in exceptions, diagnostic output, or returned tool data, and document credential rotation procedures for suspected exposure.
