T09 · Insecure Skill Coding Practices
- Location
SKILL.md:14- Finding
API Key Stored Without Explicitly Restrictive File Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14–15
Vulnerability Type: Plaintext credential exposure caused by insecure file permissions
Risk Level: MediumVulnerable Code:
bash mkdir -p ~/.config/content3 echo "c3ak_your_key_here" > ~/.config/content3/api_keyTechnical Analysis
The documented setup procedure writes a reusable Content3 bearer API key to a plaintext file but does not explicitly restrict permissions on either the configuration directory or the credential file. The resulting permissions depend on the user's current
umaskand environment. With a permissive configuration, other local users or processes may be able to read the key.The key is subsequently placed in the HTTP
Authorizationheader and can grant scopes such as content modification, review management, product management, social draft creation, and publishing. The documented*scope provides full API access. Because this is a bearer credential, possession of the key is sufficient for API authentication within its assigned scopes.Attack Path
- A user follows the documented setup procedure and writes a valid API key to
~/.config/content3/api_key. - The user's environment has a permissive
umask, causing the directory or key file to be accessible to another local principal or untrusted process. - That principal reads the plaintext bearer key from the file.
- The principal submits the stolen key in an
Authorization: Bearerheader to the Content3 API. - The principal invokes API operations allowed by the key's scopes, potentially including content access or modification, public review-link management, draft creation, and social-media publishing.
Exploitation requires local read access to the credential file; the documented commands do not independently grant remote access.
Impact Assessment
Successful exploitation exposes the privileges assigned to the compromised API key. Depending ...[truncated 641 chars]
- A user follows the documented setup procedure and writes a valid API key to
- Remediation
View remediation
Remediation Suggestions
Create the credential directory and file with explicit owner-only permissions rather than relying on the ambient
umask:bash install -d -m 700 ~/.config/content3 umask 077 printf '%s\n' "c3ak_your_key_here" > ~/.config/content3/api_key chmod 600 ~/.config/content3/api_keyAdditional hardening measures:
- Prefer an operating-system credential manager or secret store instead of a plaintext file.
- Grant each API key only the minimum scopes required for the intended workflow; avoid the
*scope. - Use separate keys for read-only, content-management, and publishing workflows.
- Rotate the key immediately if unauthorized file access is suspected.
- Document key revocation and rotation procedures.
- Require explicit user confirmation before public link creation or social-media publishing.
- Avoid printing the key in logs, command traces, diagnostics, or error messages.
