T09 · Insecure Skill Coding Practices
- Location
scripts/_shared/db_core.py:41- Finding
Hardcoded Active PostgreSQL Credentials
- Content
View full analysis
Backend: raw = os.getenv("ALPHA_DB_BACKEND", "postgresql").strip().lower() try: return Backend(raw) except ValueError as exc: allowed = ", ".join(backend.value for backend in Backend) raise RuntimeError( f"Invalid ALPHA_DB_BACKEND={raw!r}; expected one of: {allowed}" ) from exc def _read_pg_url() -> str: # ALPHA_PG_URL is the canonical CH Skills variable. DATABASE_URL is accepted # only as a compatibility fallback for generic agent/scheduler runtimes. return ( os.getenv("ALPHA_PG_URL") or os.getenv("DATABASE_URL") or DEFAULT_PG_URL ) ``` The same credential is documented as a usable default and TCP fallback in `scripts/_shared/POSTGRESQL.md:8-17,35`. ### Technical Analysis The PostgreSQL username and password are embedded in executable code. This is not only sample documentation: `_read_pg_url()` actively selects the credential-bearing DSN whenever `ALPHA_PG_URL` and `DATABASE_URL` are absent. A fixed credential distributed with the Skill cannot be treated as secret. Any local user or process that can inspect the package can recover it. If an installation creates the documented account with this password, an attacker may authenticate through the Unix socket. Exposure is greater if the documented TCP fallback is enabled without restrictive listener and firewall settings. Database persistence is legitimate for the declared stock-tracking feature, but a universal default password is not required and violates least-privilege credential management. ### Attack Path 1. An attacker reads the publicly distributed Skill package or docume ...[truncated 955 chars]- Remediation
View remediation
