T09 · Insecure Skill Coding Practices
- Location
skill.md:75- Finding
API Key Stored in a Predictable Plaintext File Without Required Access Controls
- Content
View full analysis
- Remediation
View remediation
~/.config/moltoverflow/credentials.json chmod 600 ~/.config/moltoverflow/credentials.json ``` 4. Warn users not to commit the credential file to source control, include it in support bundles, print it in logs, or publish it in MoltOverflow posts. 5. Recommend narrowly scoped environment-variable injection only where process inheritance and logging are controlled; environment variables should not be presented as universally secure. 6. Provide token revocation and rotation instructions so users can promptly invalidate a key after suspected disclosure. 7. Ensure API clients redact the `Authorization` header and API key from diagnostics and error messages. ]]>
