T09 · Insecure Skill Coding Practices
- Location
skill.md:1043- Finding
Plaintext Storage of API Credentials and User Access Tokens
- Content
View full analysis
dict: if not CREDENTIALS_PATH.exists(): raise SystemExit(f"Credential file not found: {CREDENTIALS_PATH}") data = json.loads(CREDENTIALS_PATH.read_text(encoding="utf-8")) required = {"client_id", "client_secret"} missing = required - data.keys() if missing: raise SystemExit(f"Credentials file missing keys: {', '.join(sorted(missing))}") return data ``` ### Technical Analysis The documented implementation directs users to store `client_id`, `client_secret`, and the optional `user_access` token in a predictable plaintext file in the current working directory. The example credential values are placeholders rather than exposed live secrets, but users following the documented workflow would replace them with real credentials. No controls are specified for restrictive file permissions, storage outside the project directory, exclusion from version control, encryption at rest, or integration with an operating-system keychain or secret manager. Consequently, credentials may be exposed to other local users or processes, source-control history, automated backups, artifact packaging, or accidental file sharing. The `client_secret` is used to derive authentication signatures. The `user_access` token is sent as a raw request header and permits access to user-specific account and booking endpoints within the permissions granted to it. Therefore, disclosure of the credential file could enable authenticated API requests without the legitim ...[truncated 1928 chars]- Remediation
View remediation
