T09 · Insecure Skill Coding Practices
- Location
pylinter_assist/checks/secrets.py:88- Finding
Sensitive values are reproduced in reports and posted to GitHub
- Content
View full analysis
Vulnerability Details
File Location:
pylinter_assist/checks/secrets.py:88-99,pylinter_assist/reporter.py:132-135,pylinter_assist/cli.py:51-52, 144-153
Vulnerability Type: Sensitive data exposure through diagnostic output
Risk Level: HighVulnerable Code
pylinter_assist/checks/secrets.py:88-99:python results.append( CheckResult( file=file_path, line=lineno, col=match.start() + 1, severity=Severity.ERROR, code=code, message=f"{message}: {matched_text!r}", check_name=self.name, context=stripped[:120], ) )pylinter_assist/reporter.py:132-135:python for r in sorted(bucket, key=lambda x: (x.file, x.line)): file_link = f"`{r.file}:{r.line}`" msg = r.message.replace("|", "\\|") lines.append(f"| {file_link} | {r.line} | `{r.code}` | {msg} |")pylinter_assist/cli.py:51-52:python if cfg["github"].get("post_comment") and token and repo: _post_github_comment(repo, pr_number, token, output)pylinter_assist/cli.py:144-153:python def _post_github_comment(repo: str, pr_number: int, token: str, body: str): import requests # noqa: PLC0415 url = f"https://api.github.com/repos/{repo}/issues/{pr_number}/comments" headers = { "Authorization": f"token {token}", "Accept": "application/vnd.github.v3+json", } payload = {"body": body} resp = requests.post(url, json=payload, headers=headers, timeout=30)Technical Analysis
The hardcoded-secret detector includes the complete regex match in
CheckResult.message. For HCS001, HCS002, and HCS005 findings, this may contain plaintext passwords, credential-bearing URLs, API tokens, or cloud access keys.The report renderer copies the message without redacting the sensitive substring. In JSON output, both
messageand the first 120 characters of `co ...[truncated 1726 chars]- Remediation
View remediation
Remediation Suggestions
- Never include
matched_textor the complete source line in a secret finding. - Replace the message with a fixed description containing only the finding type, filename, line, and column.
- If limited identification is necessary, mask nearly the entire value, for example
AKIA…REDACTED, and avoid retaining enough characters to make the credential usable. - Clear or redact the
contextfield for secret-related findings. - Apply centralized redaction in every renderer as a defense-in-depth control.
- Make remote comment posting opt-in rather than enabled by default.
- Add tests using representative passwords, tokens, URLs, and cloud keys. Assert that the original values never appear in text, Markdown, JSON, GitHub payloads, logs, or notification payloads.
- Document that any credentials previously posted by affected versions should be revoked and rotated.
- Never include
