T09 · Insecure Skill Coding Practices
- Location
SKILL.md:54- Finding
Bearer API Token Exposed in URL Paths and Dashboard Links
- Content
View full analysis
- Remediation
View remediation
`. - Ensure query strings, fragments, and resource paths never contain bearer credentials. 2. **Use secure dashboard authentication** - Replace permanent token-bearing dashboard links with a normal login flow, an opaque secure session cookie, or a short-lived single-use bootstrap link. - Configure cookies with `Secure`, `HttpOnly`, and an appropriate `SameSite` policy. - Expire bootstrap links immediately after account setup. 3. **Minimize credential display** - Do not print or return complete tokens unless strictly necessary. - Show only a short fingerprint or masked value, such as the final four characters. - Update agent instructions so credentials are not reproduced in conversations, logs, screenshots, or support requests. 4. **Add credential lifecycle controls** - Provide token rotation and immediate revocation. - Allow separate scoped credentials for dashboard access, read-only billing queries, and paid proxy invocation. - Prefer short-lived tokens with narrowly defined permissions. 5. **Harden logging and telemetry** - Redact existing token-shaped path segments from application, proxy, CDN, analytics, tracing, and error logs. - Prevent SDK diagnostics from recording authorization material. - Review historical logs for exposed tokens and rotate any affected credentials. 6. **Protect sensitive prompt traffic** - Continue requiring explicit user consent before proxy activation. - Present clear privacy, retention, and subprocessors disclosures before prompts are sent through Level5. - Warn users not to send secrets or regulated data unless the service is approved for that data class. ]]>
