T09 · Insecure Skill Coding Practices
- Location
SKILL.md:143- Finding
Live WordPress and MySQL credentials are exposed in terminal output
- Content
View full analysis
| grep -E 'WORDPRESS_|MYSQL_' ``` ### Technical Analysis The command prints every container environment variable whose name contains `WORDPRESS_` or `MYSQL_`. The documented environment includes sensitive values such as `WORDPRESS_DB_PASSWORD`, `WORDPRESS_ADMIN_PASSWORD`, and potentially MySQL root credentials. Although the command is intended to verify deployment configuration, it exposes complete secret values in terminal output rather than checking only the required variable names or securely capturing selected values. The output can be retained in shell logs, agent transcripts, CI/CD logs, terminal recordings, or centralized observability systems. ### Attack Path 1. An administrator or agent follows the skill and runs the documented inspection command. 2. Docker returns the container's complete WordPress and MySQL environment variables. 3. The command prints database or administrator passwords to the terminal. 4. The output is retained in an agent transcript, deployment log, shell recording, or monitoring platform. 5. An attacker with access to that retained output extracts the credentials. 6. The attacker authenticates to WordPress, MySQL, or another service that reuses the exposed credentials. ### Impact Assessment Successful exploitation may disclose WordPress administrator and database credentials. Depending on network exposure and account privileges, an attacker could: - Take control of the WordPress administrator account. - Read, modify, or delete WordPress database content. - Create malicious users or publish malicious content. - Extract personal or operational data stored by WordPress. - Use database access as a foothold for further compromise. The practical ...[truncated 147 chars]- Remediation
View remediation
