T09 · Insecure Skill Coding Practices
- Location
SKILL.md:116- Finding
Report template encourages plaintext API credential storage
- Content
View full analysis
= yesterday() status: "fulfilled" - name: "Stripe Payments" type: "stripe" config: api_key: "..." query: | created >= 24h ago status: "succeeded" - name: "Google Analytics" type: "google_analytics" config: view_id: "123456" credentials: "ga-credentials.json" ``` ### Technical Analysis The primary configuration example places Shopify and Stripe API-key fields directly inside a report YAML file. Although the values shown are placeholders, users are implicitly directed to replace them with live credentials. The documentation does not recommend environment-variable substitution, a secrets manager, restrictive file permissions, log redaction, or exclusion from source control. The Google Analytics configuration similarly references a local credential file without providing guidance about storage permissions or preventing accidental repository inclusion. This does not prove that credentials are currently exposed in the project, but it establishes an unsafe credential-handling pattern for users implementing the example. An attacker who obtains a completed configuration file or its repository history, backup, build artifact, support bundle, or logs may recover the embedded API keys. Whether those keys can be used for read-only access or state-changing operations depends on the permissions granted by the external provider. ### Attack Path 1. A user copies the documented report template. 2. The user replaces the `api_key: "..."` placeholders with active Shopify and Stripe API keys and stores a Google Analytic ...[truncated 1356 chars]- Remediation
View remediation
