T09 · Insecure Skill Coding Practices
- Location
SKILL.md:326- Finding
Hardcoded Corporate Wi-Fi Credential
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 326-328
Vulnerability Type: Plaintext hardcoded credential
Risk Level: Highmarkdown #### 9.1 WiFi 信息 - **WiFi 名称:** inspiring - **密码:** 52inspiringTechnical Analysis
The Skill embeds a corporate Wi-Fi SSID and password directly in a plaintext Markdown file. Any user or system with access to the Skill package can retrieve the credential without authentication or authorization checks.
This is particularly concerning because the document identifies itself as company-internal and states that its contents must not be shared externally. Packaging the password with the Skill expands the secret's exposure to artifact repositories, audit systems, backups, logs, and every environment where the Skill is installed.
Attack Path
- An unauthorized party obtains the Skill package through accidental publication, repository access, backup exposure, or redistribution.
- The party opens
SKILL.mdand reads lines 326-328. - The party recovers the SSID
inspiringand password52inspiring. - When within range of the wireless network, the party attempts to authenticate using the disclosed credential.
- If the credential remains valid and no additional access controls are enforced, the party gains the network access assigned to that Wi-Fi network and can attempt internal service discovery or attacks against reachable systems.
Impact Assessment
Successful exploitation may permit unauthorized connection to the corporate wireless network. The precise privileges and reachable scope depend on network segmentation, client isolation, firewall policy, and any additional identity controls. Potential consequences include unauthorized use of corporate network resources, internal reconnaissance, attacks against reachable employee devices or services, and use of the network as a launch point for further intrusion.
The artifact does not establish that th ...[truncated 157 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the SSID and password from
SKILL.mdand all distributed copies of the Skill. - Immediately rotate the exposed Wi-Fi password and invalidate the disclosed value.
- Review repository history, artifact stores, backups, logs, and published packages for retained copies of the credential.
- Replace the credential section with instructions directing authorized employees to an authenticated IT portal or support channel.
- Store wireless credentials in an access-controlled secret-management system rather than documentation or Skill configuration.
- Prefer per-user or per-device authentication, such as WPA2-Enterprise or WPA3-Enterprise with 802.1X, over a shared password.
- Segment guest, employee, and sensitive internal networks; enforce client isolation and least-privilege firewall rules.
- Add automated secret scanning to source-control and artifact-publication workflows to prevent future plaintext credential exposure.
- Review wireless authentication logs for unexpected access associated with the exposed credential.
- Remove the SSID and password from
