T09 · Insecure Skill Coding Practices
- Location
SKILL.md:55- Finding
Unencrypted Private-Key Disclosure Through Console Output and Plaintext File Storage
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 55–64, 386–389, and 432–433
Vulnerability Type: Plaintext exposure of sensitive cryptographic key material
Risk Level: HighVulnerable Code
python private_pem = private_key.private_bytes( encoding=serialization.Encoding.PEM, format=serialization.PrivateFormat.PKCS8, encryption_algorithm=serialization.NoEncryption() ).decode() print("Public Key (share this):") print(public_pem) print("\nPrivate Key (KEEP SECRET):") print(private_pem)python private_pem = private_key.private_bytes( encoding=serialization.Encoding.PEM, format=serialization.PrivateFormat.PKCS8, encryption_algorithm=serialization.NoEncryption() ).decode()python (KEYS_DIR / f"{AGENT_NAME}.pub").write_text(public_pem) (KEYS_DIR / f"{AGENT_NAME}.key").write_text(private_pem)Technical Analysis
The examples serialize the Ed25519 private key as an unencrypted PKCS#8 PEM document. The quick-start example then prints the complete private key to standard output. Standard output may be retained in terminal transcripts, CI/CD logs, agent conversation records, monitoring systems, or other log aggregation facilities.
The complete registration example also writes the unencrypted key with
Path.write_text()without explicitly enforcing owner-only permissions. The resulting access permissions depend on the process umask and surrounding filesystem configuration. On a permissively configured or shared system, other local accounts or processes may be able to read the key.These exposures are unnecessary for the declared registration workflow. The remote service only requires the public key and a signature proving possession of the private key. The private key does not need to be printed or transmitted. Although Base64 encoding and network submission appear elsewhere in the file, the encoded value is an Ed25519 signature, and th ...[truncated 1588 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove all statements that print or log private-key material. Only display the public key and a non-sensitive fingerprint.
-
Prefer an operating-system keychain, hardware-backed keystore, HSM, or managed secret store for persistent private keys.
-
If PEM storage is necessary, use encrypted PKCS#8 serialization with a strong passphrase obtained from a protected secret source:
python private_pem = private_key.private_bytes( encoding=serialization.Encoding.PEM, format=serialization.PrivateFormat.PKCS8, encryption_algorithm=serialization.BestAvailableEncryption(passphrase) ) -
Create local key files atomically with owner-only permissions such as mode
0600; do not rely solely on the ambient umask. Verify file ownership and permissions after creation. -
Prevent accidental overwrite, symbolic-link traversal, and storage in shared or synchronized directories.
-
Document secure backup, revocation, rotation, and recovery procedures for compromised identity keys.
-
Ensure logs, exception handlers, debugging tools, and agent transcripts never include private-key bytes or passphrases.
-
Clearly state that only the public key and signed proof may be transmitted to
https://id.amai.net; the private key must remain local and protected.
-
