T09 · Insecure Skill Coding Practices
- Location
debug.md:17- Finding
Diagnostic Commands Expose Container Environment Secrets
- Content
View full analysis
| tr ',' '\n'` — compare against what the app expects; the #1 cause is an env var that exists in your shell but was never passed. ``` A second recommendation repeats the behavior: ```markdown | Env vars present locally, absent in CI | `docker inspect Config.Env` diff | ``` ### Technical Analysis Docker's `.Config.Env` array contains the names and plaintext values of all environment variables configured for a container. Applications commonly receive registry tokens, database passwords, API keys, cloud credentials, signing material, and connection strings through this mechanism. The recommended commands disclose the complete array without filtering or redaction. Although Docker daemon access is already highly privileged, the command unnecessarily copies sensitive values into additional exposure surfaces, including: - Terminal output and scrollback - Agent or assistant conversation context - CI diagnostic logs - Screen recordings and shared support sessions - Incident reports or persistent runbooks - Shell wrappers that collect command output This conflicts with the Skill's stated rule that credentials must not be logged, copied, transmitted, or written into persistent memory. The declared debugging functionality only requires confirming whether expected variables exist or comparing selected values; it does not require displaying all secret values. ### Attack Path 1. A container is started with a sensitive environment variable such as `REGISTRY_TOKEN`, `DATABASE_URL`, or `AWS_SECRET_ACCESS_KEY`. 2. A crash or production discrepancy leads an operator or Agent to follow the diagnostic guidance. 3. The prescribed `docker inspect` command prints every environment variable ...[truncated 762 chars]- Remediation
View remediation
\ | sed 's/=.*$/=/' ``` 3. When checking a particular variable, report only whether it is present: ```bash docker inspect -f '{{range .Config.Env}}{{println .}}{{end}}' \ | cut -d= -f1 \ | grep -Fx 'EXPECTED_VARIABLE' ``` 4. Add an explicit warning that `docker inspect`, `docker compose config`, and similar commands may expose plaintext secrets. 5. Prohibit raw environment output from being copied into Agent memory, artifacts, tickets, or runbooks. 6. Recommend mounted secret files or dedicated secret-management mechanisms instead of environment variables where the deployment platform supports them. 7. If values must be compared, perform the comparison locally and return only a match/mismatch result. ]]>
