T09 · Insecure Skill Coding Practices
- Location
scripts/run-task.sh:135- Finding
Persistent Plaintext Storage of an SSH Private Key
- Content
View full analysis
~/.ssh/automate_key chmod 600 ~/.ssh/automate_key log "🔑 SSH key loaded" fi ``` ### Technical Analysis When `AUTOMATE_SSH_KEY` is present, the script writes its complete value to the stable path `~/.ssh/automate_key`. Although the file is assigned mode `600`, the script does not: - Use the key for any SSH operation. - Store it in an ephemeral task-specific location. - Register an exit handler to remove it. - Check whether the destination is an existing regular file or symbolic link. - Restrict the permissions of the containing `.ssh` directory. - Prevent subsequent jobs running under the same account from reading it. File mode `600` protects the key from other operating-system users, but not from later processes, jobs, or compromised tools operating as the same user. The stable filename also causes every invocation to overwrite the previous key. The behavior exceeds the current implementation's operational needs. Task execution only generates Markdown and JSON result files; no active code consumes the SSH key. ### Attack Path 1. A workflow or operator invokes `scripts/run-task.sh` with `AUTOMATE_SSH_KEY` containing a valid private key. 2. The script writes the private key to `~/.ssh/automate_key`. 3. Task processing finishes, but the script performs no credential cleanup. 4. A later process, compromised dependency, malicious task, or separate job running under the same account reads the retained file. 5. The attacker uses the key aga ...[truncated 956 chars]- Remediation
View remediation
"$SSH_TEMP_DIR/automate_key" chmod 600 "$SSH_TEMP_DIR/automate_key" fi ``` ]]>
