T09 · Insecure Skill Coding Practices
- Location
SKILL.md:368- Finding
Plaintext Storage of API Credentials and Private-Key Metadata
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is for a real financial API workflow, but it asks agents to handle powerful crypto-payment credentials and execute high-impact transactions with weak scoping and storage safeguards.
Install only if you are comfortable letting an agent handle crypto-payment credentials and signed financial API requests. Use test credentials first, avoid saving secrets in .local.md, keep the PEM key outside shared or synced folders, verify the Base URL belongs to the intended service before any request, and manually confirm every amount, asset, network, destination address, and contract target before execution.
SKILL.md:368Plaintext Storage of API Credentials and Private-Key Metadata
SKILL.md:103API Key and Sensitive Transaction Data Exposed Through Command-Line Arguments
SKILL.md:94Configurable Base URL Can Redirect Credentials to an Untrusted Service
SKILL.md:103Referenced Security-Critical Request Script Is Missing From the Package
The skill is designed to access high-value credentials: an API signing token and a PEM private key used to authorize financial API requests. Even if operationally necessary, instructing the agent to retrieve and use these secrets materially increases risk because compromise or misuse could enable unauthorized crypto purchase or transfer actions.
- **BASE_URL**: API base URL
- **CLIENT_ID**: Client identifier
- **API_KEY**: The sign access token
- **PEM_PATH**: Absolute path to the RSA private key PEM file
Use the account marked `(default)` in `.local.md`.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
## Security
### Credential Display Rules
- **API Key**: Show first 5 + last 4 characters only (e.g., `2zefb...06h`)
- **PEM Private Key**: NEVER display content. NEVER display the file path.
The skill explicitly supports fiat-to-crypto purchases and direct on-chain sends, both of which can be irreversible and high-risk if the user provides the wrong address, network, amount, or merchant parameters. Although the skill documents mechanics, it lacks a prominent step requiring explicit user confirmation and warning about irreversible transfers before initiating purchase or send flows.
The skill instructs storing API credentials and the PEM private-key path in .local.md, which is plaintext configuration storage, but does not prominently warn users about the security risks of local plaintext secret storage. This increases the chance of credential exposure through backups, filesystem compromise, accidental sharing, or inclusion in version control.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| openssl dgst -sha256 -sign "test.pem" \
| openssl enc -base64 -A)
curl --location --request POST "https://api.commonservice.io/papi/v1/ramp/connect/buy/payment-method-list" \
--header "X-Tesla-ClientId: your-client-id" \
--header "X-Tesla-SignAccessToken: your-api-key" \
--header "X-Tesla-Signature: $signature" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| openssl dgst -sha256 -sign "test.pem" \
| openssl enc -base64 -A)
curl --location --request POST "https://api.commonservice.io/papi/v1/ramp/connect/buy/payment-method-list" \
--header "X-Tesla-ClientId: your-client-id" \
--header "X-Tesla-SignAccessToken: your-api-key" \
--header "X-Tesla-Signature: $signature" \
No suspicious patterns detected.