T09 · Insecure Skill Coding Practices
- Location
SKILL.md:76- Finding
Plaintext SMTP Credential Persistence in Shell Startup Configuration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 76–81
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Mediumbash **Permanent configuration (add to ~/.zshrc):** ```bash echo 'export EMAIL_SENDER="your_email@126.com"' >> ~/.zshrc echo 'export EMAIL_SENDER_NAME="Your Name"' >> ~/.zshrc echo 'export EMAIL_PASSWORD="your_smtp_password"' >> ~/.zshrc echo 'export EMAIL_RECIPIENT="recipient@example.com"' >> ~/.zshrc source ~/.zshrctext ### Technical Analysis The documented configuration procedure instructs users to persist an SMTP password as plaintext in `~/.zshrc`. Shell startup files are not dedicated secret stores and may be read by other processes operating under the same account, included in backups, copied during troubleshooting, or accidentally committed or shared. Loading the value from an environment variable in the Python script prevents hardcoding it in source code, but it does not protect the secret when the instructions persist that variable in an ordinary plaintext file. Sourcing the file also exports the credential into the environment of subsequently launched child processes. ### Attack Path 1. A user follows the documented permanent configuration procedure. 2. The SMTP password is written verbatim to `~/.zshrc`. 3. An attacker, malicious local process, compromised development tool, backup reader, or diagnostic collector obtains read access to the file. 4. The attacker extracts `EMAIL_SENDER` and `EMAIL_PASSWORD`. 5. The attacker authenticates to the configured SMTP account and sends email as the victim, subject to the account's permissions and provider controls. ### Impact Assessment Successful exploitation exposes the SMTP credential and associated sender identity. An attacker may send unauthorized messages, distribute spam or phishing email, damage sender reputation, and potentially cause account suspension. The issue does not directly grant e ...[truncated 139 chars]- Remediation
View remediation
Remediation Suggestions
- Do not recommend storing passwords in
~/.zshrc,~/.bashrc, or other general-purpose shell startup files. - Store the SMTP credential in an operating-system keychain, credential manager, or managed secret service and retrieve it only when the report is sent.
- Prefer provider-issued, narrowly scoped application passwords over the primary email account password.
- If file-based storage is unavoidable, use a dedicated secrets file outside the repository, restrict it to mode
0600, and ensure it is excluded from version control and backups where appropriate. - Avoid globally exporting the credential to every child process in the interactive shell.
- Document credential rotation and immediate revocation procedures.
- Replace the permanent configuration example with a secure wrapper that reads the secret from a keychain at runtime.
- Do not recommend storing passwords in
