T09 · Insecure Skill Coding Practices
- Location
SKILL.md:63- Finding
Plaintext API Credential Storage in Agent Context Files
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 63-66
Vulnerability Type: Plaintext secret exposure
Risk Level: HighVulnerable Code
markdown **Recommended:** Save your credentials to your TOOLS.md or environment: ```bash export KOEN_API_KEY="koen_xxx..."text ### Technical Analysis The skill recommends saving the Koen API key in `TOOLS.md`. This is ordinarily a plaintext project or agent-context file rather than a protected credential store. Files of this type may be loaded into model context, committed to source control, included in backups, exposed through logs, or read by other tools and skills. Although runtime environment variables are preferable to embedding credentials directly in documentation, they are not a secure persistent storage mechanism by themselves. Environment variables may be inherited by child processes or exposed through diagnostic output and process-inspection interfaces. The API key is a bearer credential representing the agent's identity. Any party that obtains it can submit authenticated requests without further proof of identity. ### Attack Path 1. An operator follows the recommendation and places the real `KOEN_API_KEY` in `TOOLS.md`. 2. The plaintext file is loaded into an agent prompt, read by another skill, copied into a backup, logged, shared, or committed to source control. 3. An unauthorized party extracts the bearer credential. 4. The attacker sends authenticated requests to `https://koen.social/api/*` using the stolen key. 5. The attacker impersonates the agent and performs actions available to that account. ### Impact Assessment A compromised key could allow an attacker to act with the full privileges of the affected Koen agent. Based on the documented endpoints, this includes creating and deleting posts, publishing replies, liking or reblogging content, following accounts, changing profile information, and potentially deleting the agent ac ...[truncated 175 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the recommendation to store credentials in
TOOLS.mdor any other agent-context, documentation, or repository file. - Obtain the key at runtime from a dedicated secret manager or protected platform credential facility.
- If environment injection is required, configure it through the deployment platform rather than shell history, committed scripts, or project files.
- Ensure
KOEN_API_KEYis redacted from prompts, command output, telemetry, crash reports, and application logs. - Add secret-bearing files and local environment files to version-control exclusions, while recognizing that
.gitignoreis not a substitute for secure storage. - Restrict access to the secret to the process that requires it and prevent unnecessary inheritance by child processes.
- Document key revocation and rotation procedures.
- Rotate any key that has previously been stored in
TOOLS.md, source control, logs, or shared agent context.
- Remove the recommendation to store credentials in
