T09 · Insecure Skill Coding Practices
- Location
SKILL.md:84- Finding
Long-Lived Bearer Token Stored in Plaintext Configuration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:84-108andSKILL.md:245-247
Vulnerability Type: Plaintext storage of a long-lived bearer token
Risk Level: MediumVulnerable Code
json { "mcpServers": { "pndr": { "baseUrl": "https://pndr.io/mcp", "headers": { "Authorization": "Bearer YOUR_ACCESS_TOKEN" } } } }json { "mcpServers": { "pndr": { "url": "https://pndr.io/mcp", "headers": { "Authorization": "Bearer YOUR_ACCESS_TOKEN" } } } }text Pndr uses OAuth 2.0 client credentials flow. Access tokens expire after 1 year (365 days). To refresh your token, repeat the `curl` command from step 2 and update your mcporter config with the new Bearer token.Technical Analysis
The documented configuration embeds a bearer access token directly in the
mcporteror Claude Desktop configuration file. Bearer tokens grant access based solely on possession, so any process or user capable of reading the configuration can reuse the token without knowing the OAuth client secret.The documented one-year validity period substantially extends the period during which a copied token may be abused. Configuration files may also be exposed through overly broad file permissions, source-control commits, workstation backups, diagnostic archives, support bundles, malware, or other local processes.
The file contains placeholders rather than an actual secret, so no credential is directly disclosed by the audited project. The vulnerability is in the recommended credential-storage practice and prolonged token lifetime.
Attack Path
- A user follows the instructions and places a real Pndr bearer token directly in an MCP configuration file.
- An attacker obtains read access to that file through local account compromise, weak file permissions, a leaked backup, an accidental repository commi ...[truncated 1080 chars]
- Remediation
View remediation
Remediation Suggestions
- Avoid embedding bearer tokens directly in ordinary JSON configuration files. Support environment-variable interpolation or references to an external credential provider.
- Store credentials in an operating-system secret facility such as macOS Keychain, Windows Credential Manager, Linux Secret Service, or a dedicated secrets manager.
- Reduce access-token validity from one year to a short lifetime and use a securely stored refresh token or interactive OAuth authorization when renewal is required.
- Provide explicit token revocation and rotation mechanisms, including instructions for immediate revocation after suspected exposure.
- Apply least-privilege scopes so read-only use does not receive write or deletion permissions.
- Restrict configuration-file permissions to the owning user and warn users not to commit configuration files, include them in support bundles, or store them in unencrypted backups.
- Add secret-scanning rules for Pndr token formats and document incident-response steps for leaked credentials.
- Where plaintext configuration is unavoidable, clearly disclose the risk and recommend full-disk encryption, restrictive permissions, and regular credential rotation.
