T09 · Insecure Skill Coding Practices
- Location
SKILL.md:164- Finding
Insecure Recommendation to Store an API Key in a Plaintext .env File
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 164–166
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: MediumVulnerable Code
markdown - Persist the returned `apiKey` to a secure local store (`.env`, `1Password`, Cloudflare Secret, Vault, etc.) BEFORE rendering the response to the user.Technical Analysis
The skill presents a
.envfile as equivalent to managed secret-storage systems such as Vault or 1Password. A conventional.envfile is an unencrypted plaintext file and is not inherently secure. The instructions do not require restrictive filesystem permissions, exclusion from source control and build artifacts, encryption at rest, or separation from files accessible to unrelated processes.The returned API key is a long-lived bearer credential used by downstream Pre-Market operations. Possession of the raw key is sufficient to authenticate as the registered agent. Although the skill correctly prohibits logging the key, recommending an inadequately protected
.envfile can still expose it through source-control commits, deployment bundles, backups, support archives, CI artifacts, or access by other local users and processes.The same insecure recommendation is also repeated in
README.md, lines 91–93:markdown **The `apiKey` is returned exactly once.** Persist it to a secure store (`.env`, `1Password`, Vault, Cloudflare Secret, …) before rendering the response.Attack Path
- The agent follows the documented recommendation and writes the returned
pmk_…API key to a project-level.envfile. - The file is left with permissive filesystem permissions, copied into an application image or artifact, included in a backup, or accidentally committed to source control.
- An attacker with access to the repository, artifact, backup, deployment image, or local filesystem reads the plaintext API key.
- The attacker supplies the stolen ...[truncated 896 chars]
- The agent follows the documented recommendation and writes the returned
- Remediation
View remediation
Remediation Suggestions
- Remove
.envfrom the list of storage mechanisms described as secure. Prefer an operating-system keychain or a managed secret store such as Vault, 1Password, or a cloud-provider secret manager. - If
.envsupport is operationally necessary, explicitly require all of the following controls:- Store the credential outside the source tree where possible.
- Add the file to
.gitignoreand verify it is not already tracked. - Apply owner-only filesystem permissions, such as mode
0600on Unix-like systems. - Exclude the file from containers, deployment archives, logs, backups, crash reports, and support bundles unless those systems provide appropriate encryption and access controls.
- Never print the value through shell tracing, CI output, telemetry, or error messages.
- Write the credential atomically without exposing it in command-line arguments or process listings.
- Document a clear revocation and rotation procedure for suspected exposure, including immediate invalidation of the previous key.
- Update both
SKILL.mdandREADME.mdso their credential-storage guidance is consistent.
- Remove
