Credential Access
- Category
- Privilege Escalation
- Confidence
- 90% confidence
- Finding
Storing authentication material in
${XDG_CONFIG_HOME:-~/.config}/ai-shifu/credentials.jsoncreates a concrete credential-access surface, especially if file permissions, encryption, rotation, and revocation are not enforced. Because this skill performs authenticated platform actions and accesses learner/course data, token theft could enable unauthorized account access, content modification, analytics access, or impersonation.- Content
md - Print course links with `Admin console`, `Preview URL`, and optional `Published URL` labels, without explanatory text. Open each delivered course or lesson's admin page in the Agent's built-in browser after successful operations and verification, respecting browser opt-outs. Report queued navigation as pending and keep course results intact when the browser is unavailable or opening fails. - Ask new platform users to choose their current region (China or Other countries or regions), initialize the matching service silently, and remember it outside the Skill package. Preserve explicit service configuration, support custom deployments on request, and block platform calls until configured. Match official contact links to the selected service and preserve resource URLs returned by image uploads without assuming a CN domain. - Replace SMS login with a browser authorization flow: `login` prints a verification link and pairing code, `login --wait` collects the token once the user approves the request on the AI-Shifu approval page, and no command sends a text message any more. Credentials move from the skill's `.env` to `${XDG_CONFIG_HOME:-~/.config}/ai-shifu/credentials.json` so upgrading or reinstalling the skill no longer signs the user out, and a token left behind by an older version is migrated on first run. - Use platform-supplied learner context in Course Prompts to personalize open expression while preserving the course author's intended audience, each Teaching Prompt's fixed decisions, and neutral behavior when no relevant learner profile is available. - Initialize a missing `.env` from `.env.example` before every course CLI command, allow an optional `SHIFU_BASE_URL`, keep `https://app.ai-shifu.cn` as the fallback, and preserve the configured URL when SMS login updates the token. - Add a low-friction teacher-avatar follow-up after teacher identity intake and a version-aware `set-avatar` CLI path that accepts JPG/PNG, auto-compresses to 2 MB, warns on non-square ...[truncated 24 chars]
