T09 · Insecure Skill Coding Practices
- Location
__init__.py:15- Finding
Jenkins Credentials Stored in a Plaintext Project Configuration File
- Content
View full analysis
Vulnerability Details
File Location:
__init__.py:15-25; related configuration inconfig.json:1-5
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: HighVulnerable Code
python # 加载配置文件 config_path = Path(__file__).parent / "config.json" with open(config_path, "r", encoding="utf-8") as f: self.config = json.load(f) # 连接 Jenkins self.jenkins = Jenkins( baseurl=self.config["base_url"], username=self.config["username"], password=self.config["api_token"], timeout=30 )The corresponding tracked configuration structure is:
json { "base_url": "Jenkins地址", "username": "用户名", "api_token": "授权码" }Technical Analysis
The implementation loads the Jenkins username and API token directly from
config.jsoninside the project directory. This conflicts withSKILL.md, which states thatJENKINS_URL,JENKINS_USER, andJENKINS_TOKENshould be supplied through environment variables.Although the audited file contains placeholders rather than an active secret, the implemented configuration flow requires users to replace those placeholders with credentials. This makes it likely that operational tokens will be included in source-control commits, packaged skill archives, backups, container images, or filesystem snapshots. File permissions are not restricted or validated.
Attack Path
- A user replaces the placeholders in
config.jsonwith a working Jenkins username and API token. - The project directory is committed, archived, copied, backed up, or exposed to another local account.
- An attacker reads
config.jsonand extracts the Jenkins endpoint and credentials. - The attacker authenticates directly to Jenkins using the stolen token.
- The attacker exercises all permissions granted to the compromised Jenkins account, potentially including reading job data and logs, triggering parameterized builds, or stopp ...[truncated 747 chars]
- A user replaces the placeholders in
- Remediation
View remediation
Remediation Suggestions
- Remove
usernameandapi_tokenfrom tracked configuration files. - Load
JENKINS_URL,JENKINS_USER, andJENKINS_TOKENfrom environment variables or a dedicated secrets manager. - Keep only a non-sensitive example file such as
config.example.json. - Add the operational configuration file to
.gitignoreif a local file must remain supported. - Fail initialization when required credentials are absent instead of falling back to embedded values.
- Restrict filesystem permissions on any unavoidable local secret file to the service account only.
- Add secret scanning to pre-commit hooks and CI.
- Rotate any Jenkins token that has previously been stored in or committed through
config.json. - Assign the Jenkins account only the minimum permissions needed by the skill.
- Remove
