T09 · Insecure Skill Coding Practices
- Location
scripts/register_agent.py:16- Finding
Authentication Key and Private Game Data Transmitted Over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
` header or another protected authentication mechanism. 5. Use separate, revocable, scoped tokens for read-state, write-state, messaging, and telemetry operations rather than one key authorizing every action. 6. Avoid printing full credentials or credential-bearing URLs. Redact keys in console output and logs. 7. Apply short token lifetimes, key rotation, rate limiting, and anomaly detection on the server. 8. Ensure chat and state APIs perform authorization checks for every operation rather than merely checking that a syntactically valid key was supplied. 9. Update `SKILL.md`, metadata, scripts, and all reference documentation so no plaintext endpoint remains. ]]>
