T09 · Insecure Skill Coding Practices
- Location
SKILL.md:12- Finding
Hardcoded SuperMemory API Credential in Documentation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-15
Vulnerability Type: Hardcoded secret
Risk Level: HighVulnerable Code
bash export SUPERMEMORY_API_KEY="[REDACTED_EXPOSED_TOKEN]"The source contains a complete token beginning with the
sm_prefix. Its value is redacted in this report to avoid further credential exposure.Technical Analysis
An apparent SuperMemory API credential is embedded directly in distributable documentation. Users, source repository readers, package recipients, and automated indexing systems can retrieve the credential without authorization.
The scripts subsequently use
SUPERMEMORY_API_KEYas a bearer token:bash -H "Authorization: Bearer $API_KEY"Bearer tokens grant their holder the token's associated capabilities without requiring additional proof of identity. Consequently, exposure of this value may permit third parties to invoke SuperMemory API operations under the affected account.
Attack Path
- An attacker downloads, clones, or otherwise obtains the skill package.
- The attacker reads the exported token from
SKILL.md. - The attacker supplies it in an
Authorization: BearerHTTP header. - The attacker invokes SuperMemory API endpoints.
- Subject to the token's actual permissions, the attacker accesses, searches, or contaminates stored memory data and consumes account quotas.
Impact Assessment
The attacker may obtain all privileges assigned to the exposed API token. The potential scope includes unauthorized API usage, quota consumption, insertion of attacker-controlled memories, and disclosure of stored information if the token permits retrieval. The exact account and data scope depends on server-side permissions assigned to the credential.
- Remediation
View remediation
Remediation Suggestions
-
Revoke the exposed credential immediately through the SuperMemory account or credential-management interface.
-
Generate a replacement token and ensure it is not committed to source control or included in documentation.
-
Replace the example with a nonfunctional placeholder:
bash export SUPERMEMORY_API_KEY="your-api-key" -
Load credentials from secure runtime configuration, such as an approved secret manager or protected environment injection mechanism.
-
Review repository history, package releases, logs, and mirrors because deleting the current value does not remove earlier copies.
-
Audit the affected account for unexpected API requests, memory additions, searches, and quota usage.
-
Add secret-scanning checks to pre-commit and continuous-integration workflows.
-
