T09 · Insecure Skill Coding Practices
- Location
SKILL.md:46- Finding
Hardcoded Shared API Key Exposed in Skill Documentation
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 } ``` 3. Replace documentation credentials with an unmistakable placeholder such as `YOUR_API_KEY`. 4. Revoke or rotate the exposed key if it was not expressly designed as a permanently public anonymous token. 5. If anonymous trial access is required, implement it server-side without distributing a reusable credential. Apply strict per-IP or per-installation rate limits and abuse monitoring. 6. Prefer a dedicated secret store or environment variable over plaintext configuration where supported. 7. Ensure configuration files containing user-specific keys have restrictive permissions, such as mode `0600`. 8. Add automated secret scanning to the publication workflow to prevent future credentials from being committed or packaged. ]]>
