T09 · Insecure Skill Coding Practices
- Location
SKILL.md:14- Finding
API Key Exposed Through Shell Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14–18
Vulnerability Type: Credential exposure through plaintext shell output
Risk Level: MediumVulnerable Code
markdown Read the API key from the environment variable `FFHUB_API_KEY`: ```bash echo $FFHUB_API_KEYtext ### Technical Analysis The skill instructs the agent to execute `echo $FFHUB_API_KEY`, which writes the complete bearer credential to standard output. Tool output may be retained in agent transcripts, execution logs, debugging systems, or other observability infrastructure. Displaying the secret is unnecessary to determine whether the environment variable is configured. Because the same key is subsequently intended for use as a bearer token in FFHub API requests, anyone who obtains the exposed value may be able to authenticate as the affected user. ### Attack Path 1. A user invokes the FFHub skill with `FFHUB_API_KEY` configured. 2. The agent follows the authentication instructions and runs `echo $FFHUB_API_KEY`. 3. The complete API key appears in captured shell output. 4. A party with access to the conversation transcript, tool logs, or execution telemetry obtains the key. 5. The exposed key is reused against FFHub endpoints until it is revoked or expires. This finding does not establish that logs are publicly accessible; exploitation requires access to a location where the shell output was retained. ### Impact Assessment Successful exploitation could permit unauthorized FFHub API access within the permissions assigned to the exposed key. Potential effects include consumption of the victim's API quota, submission or inspection of processing tasks where authorized by the API, and access to associated task results. This issue does not provide local system privilege escalation by itself.- Remediation
View remediation
Remediation Suggestions
Do not print the credential. Check only whether the variable is defined and nonempty:
bash if [ -z "${FFHUB_API_KEY:-}" ]; then echo "FFHUB_API_KEY is not set" exit 1 fiAdditional hardening measures:
- Pass the key directly to
curlwithout displaying or logging it. - Ensure shell tracing such as
set -xis disabled while handling credentials. - Redact authorization headers and secret environment variables from agent transcripts and execution logs.
- Use narrowly scoped, short-lived API keys where supported.
- Revoke and rotate any key that may already have been exposed through tool output.
- Pass the key directly to
