T09 · Insecure Skill Coding Practices
- Location
scripts/quick-scan.sh:36- Finding
Detected secrets are disclosed through console and CI output
- Content
View full analysis
/dev/null | head -5 || true) if [[ -n "$SECRETS" ]]; then echo "⚠️ Potential secrets found:" echo "$SECRETS" else ``` ### Technical Analysis The quick scanner stores complete source lines matched by the secret-detection expression in `SECRETS` and then prints those lines without redacting the detected value. A matching line can contain an entire password, API key, or authentication token. Although the scanner needs to identify the location of suspected credentials, disclosing the complete matching line is unnecessary. When the script runs in a terminal, build pipeline, release workflow, or hosted CI service, its standard output may be retained in logs and made available to a broader group than the original source file. The scanner's own pattern definitions can also produce false positives when it scans itself, as demonstrated by the bundled historical audit report. That accuracy issue does not eliminate the disclosure risk when an actual secret is present. ### Attack Path 1. A target skill contains a plaintext credential matching one of the scanner's regular expressions. 2. A developer or automated pipeline invokes `scripts/quick-scan.sh` against that skill. 3. `grep` captures the complete credential-bearing source line. 4. `echo "$SECRETS"` writes the complete line, including the credential, to standard output. 5. Terminal recording, CI log retention, or centralized log collection preserves that output. 6. A user with access to those logs obtains and reuses the exposed credential. ### Impact Assessment This issue does not direct ...[truncated 453 chars]- Remediation
View remediation
