T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:46- Finding
API Key Persisted in a Plaintext Environment File
- Content
View full analysis
Vulnerability Details
File Location:
scripts/config.py:46-64
Vulnerability Type: Plaintext storage of sensitive credentials
Risk Level: MediumVulnerable Code
python def save_api_key_to_env(api_key: str) -> bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return TrueTechnical Analysis
The function stores the user-provided API key directly in a plaintext
.envfile. It does not use an operating-system credential store, encrypt the credential, request explicit consent for persistent storage, enforce restrictive file permissions, or protect against writing through a symbolic link.Path.write_text()creates or overwrites the file according to the process umask. On systems with an insufficiently restrictive umask, other local users or processes may be able to read the credential. The file may also be unintentionally included in source-control commits, workspace archives, support bundles, or backups.The credential is legitimately required by the declared API-backed functionality and is sent over HTTPS in the
XBY-APIKEYheader. The vulnerability is therefore not the authenticated network request itself, but the unnecessary and insufficiently protected persistent plaintext copy.Attack Path
- The Skill instructs the agent to ask the user for an API key whe ...[truncated 1534 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer session-only credential handling through a process environment variable. Do not persist the key unless the user explicitly requests persistence.
- Store persistent credentials in an operating-system secret manager or platform-provided encrypted credential store.
- If
.envstorage must remain supported:- Obtain explicit user consent before writing the key.
- Create the file atomically with owner-only permissions such as
0600. - Verify that the destination is a regular file and reject symbolic links.
- Use an application-specific configuration directory rather than the current working directory.
- Add
.envto.gitignoreand document that it must never be committed or shared.
- Avoid keeping duplicate persistent copies of the credential.
- Provide API-key rotation and revocation guidance in case the workspace or
.envfile is exposed. - Redact credentials from exceptions, logs, diagnostics, backups, and support bundles.
