T09 · Insecure Skill Coding Practices
- Location
references/human-cards.md:37- Finding
Long-Lived Tencent Cloud Credentials Are Instructed to Be Submitted Through Chat
- Content
View full analysis
Vulnerability Details
File Location:
references/human-cards.md, lines 37–48
Vulnerability Type: Plaintext credential exposure through retained conversation history
Risk Level: HighVulnerable instructions:
text ## C0-Remote: The agent and user are not on the same computer (the agent runs in the cloud or on a server) In this case, the web wizard cannot be used because the user's browser cannot access 127.0.0.1 on the agent's machine. Select options in this order: 1. Platform-provided secrets or environment-variable settings: ask the user to enter SecretId and SecretKey into the platform's secret settings as TENCENTCLOUD_SECRET_ID and TENCENTCLOUD_SECRET_KEY. 2. If the platform has no such settings: the only option is to ask the user to send the credentials in the conversation. After receiving them, the agent immediately calls tcapi.save_credential() to save them for long-term use. Explain that: - The credentials will remain in the conversation history, but their permissions are limited. - If concerned about leakage, the user can disable agent-ops and provide a new credential pair. Do not ask the user to rotate the credentials after use, because the agent would no longer be able to continue long-term work.The quoted text is an English translation of the operative instructions at the specified location.
Technical Analysis
When the agent runs remotely and no platform secret facility exists, the Skill explicitly directs the user to submit a Tencent Cloud
SecretIdandSecretKeythrough the conversation. It acknowledges that the credentials remain in conversation history, directs the agent to persist them usingtcapi.save_credential(), and discourages rotation after use.This moves long-lived authentication material from a dedicated secret-handling boundary into the agent platform's conversation-storage boundary. Conversation records may be retained in model context, platform ...[truncated 2568 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction that permits Tencent Cloud credentials to be submitted through conversation messages.
- Require one of the following protected enrollment mechanisms:
- A platform-managed secret store.
- Environment-variable injection through a protected configuration interface.
- A user-run local enrollment utility that writes directly to the credential file.
- A dedicated authenticated secret-submission channel that excludes values from conversation history, logs, telemetry, and model context.
- If no protected channel is available, terminate enrollment with a clear explanation instead of accepting credentials through chat.
- Prefer short-lived Tencent Cloud credentials with a session token where supported. Apply narrow expiration periods and resource-level restrictions.
- Do not discourage credential rotation. Provide a documented rotation procedure that replaces stored credentials without interrupting service longer than necessary.
- Revoke and rotate any credential pairs previously submitted through conversations.
- Add explicit checks or agent instructions that reject messages containing apparent Tencent Cloud secrets and direct the user to a protected setup method.
- Retain the existing least-privilege policy and local file protections, but further scope access to only the specific resources the user has selected where Tencent Cloud policy semantics permit it.
