T09 · Insecure Skill Coding Practices
- Location
config.json:6- Finding
Plaintext Storage of VK Service Token
- Content
View full analysis
Vulnerability Details
File Location:
config.json, lines 6-9
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Mediumjson "auth": { "vk_service_token": "PASTE_YOUR_TOKEN_HERE", "api_version": "5.131" },Technical Analysis
The configuration provides a field intended to be replaced with a real VK service token. The project documentation directs users to place their service token into the configuration file, causing the credential to be stored as plaintext inside the Skill directory.
Plaintext configuration secrets may be exposed through source-control commits, backups, shared archives, overly permissive filesystem access, diagnostic bundles, or access by other local processes. Although the distributed file contains only a placeholder and no active credential, following the documented setup procedure creates the insecure condition.
Attack Path
- A user replaces
PASTE_YOUR_TOKEN_HEREwith a valid VK service token. - The populated
config.jsonremains in the Skill directory as plaintext. - The file is inadvertently committed, archived, shared, backed up, or read by an unauthorized local user or process.
- An attacker extracts the token from the
vk_service_tokenfield. - The attacker submits VK API requests using the stolen token.
- The attacker gains access to the VK API operations and data permitted by that token until it is revoked or expires.
Impact Assessment
Successful exploitation can compromise the confidentiality of the VK service token and permit unauthorized VK API access within the token's assigned scope. The precise impact depends on the permissions attached to the token. Potential consequences include unauthorized access to API-visible information, consumption of API quotas, and actions attributable to the associated VK application.
This issue does not directly provide operating-system privilege escalation or arbitrary code executi ...[truncated 88 chars]
- A user replaces
- Remediation
View remediation
Remediation Suggestions
- Remove the token value from the tracked configuration file and load it from an environment variable, such as
VK_API_TOKEN. - Retain only a non-sensitive reference in configuration, for example:
json "auth": { "token_env": "VK_API_TOKEN", "api_version": "5.131" } - Prefer an operating-system credential store or managed secret service when available.
- Add local files capable of containing real credentials to
.gitignore, and provide a sanitized example configuration separately. - Restrict secret-file permissions to the account running the Skill.
- Ensure logs, error reports, and generated output never include the token or request URLs containing it.
- Validate at startup that the placeholder has not been treated as a real token, without printing the supplied credential.
- Document token rotation and immediate revocation procedures for suspected exposure.
- Apply the minimum VK permissions necessary for reading the intended public data.
- Remove the token value from the tracked configuration file and load it from an environment variable, such as
