T09 · Insecure Skill Coding Practices
- Location
scripts/scanner.py:126- Finding
Plaintext Secrets Are Included in JSON Scan and Report Output
- Content
View full analysis
50 else matched_value, "auto_fixable": False }) ``` The scan command directly serializes the resulting object: ```python # scripts/main.py:77-79 if args.format == "json": print(json.dumps(results, indent=2, ensure_ascii=False)) ``` The report generator carries the same finding objects into JSON reports: ```python # scripts/report.py:46-49 if include_secrets: secrets_results = scan_secrets(deep=deep) report["secrets_findings"] = secrets_results["findings"] report["secrets_summary"] = secrets_results["summary"] ``` ```python # scripts/report.py:68-70 def format_json(report: Dict) -> str: """Format report as JSON.""" return json.dumps(report, indent=2, ensure_ascii=False) ``` Reports may then be persisted to a caller-selected path: ```python # scripts/main.py:156-165 if output: if args.output: Path(args.output).write_text(output) print(f"Report saved to: {args.output}") else: print(output) ``` ### Technical Analysis The scanner correctly creates a masked representation in `matched`, but it also retains the original detected value in `full_match`. Values of 50 characters or fewer are stored without redaction. Longer values expose their first 50 characters, which is sufficient to reveal many API keys, passwords, and authentication token ...[truncated 1958 chars]- Remediation
View remediation
