T09 · Insecure Skill Coding Practices
- Location
SKILL.md:62- Finding
Sensitive Configuration Values May Be Exposed During Environment Cross-Referencing
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 62
Vulnerability Type: Excessive inspection of secret-bearing configuration files
Risk Level: MediumComplete Code Snippet:
markdown **Detection method:** Cross-reference every `process.env`, `os.environ`, `ENV[]` read against actual `.env`, `.env.example`, CI/CD configs, and deployment manifests.Technical Analysis
The Skill directs the agent to inspect actual
.env, CI/CD configuration, and deployment manifest files. These resources frequently contain API keys, access tokens, passwords, private endpoints, and other deployment secrets.Comparing environment-variable references with declared variable names is relevant to the stated dependency-analysis function. However, reading or retaining the corresponding values is not necessary. The instruction does not require key-only parsing, value redaction, explicit authorization, repository-boundary enforcement, or exclusion of secret-bearing CI/CD fields. Consequently, secret values could enter the model context, tool logs, conversation history, or generated report.
No executable network request or instruction to transmit collected information externally was identified. References to outbound payloads and APIs describe static-analysis targets, while the Skill explicitly claims “Zero API calls.” The risk is therefore inadvertent local disclosure rather than confirmed exfiltration.
Attack Path
- A user invokes the Skill against a repository or workspace.
- The agent follows the instruction to cross-reference environment reads against actual
.env, CI/CD, or deployment files. - The agent opens a file containing plaintext credentials or tokens.
- Complete secret values enter the agent context or tool execution logs even though only variable names are needed.
- The values may subsequently be reproduced in diagnostic output, retained in conversation history, or exposed to users who can acc ...[truncated 754 chars]
- Remediation
View remediation
Remediation Suggestions
- Inspect configuration keys and schemas only; never load secret values when determining whether an environment variable is declared.
- Parse
.envfiles using a key-only routine that discards text after the assignment delimiter before it enters model context or logs. - Redact values from CI/CD configurations and deployment manifests, including encoded or templated secret fields.
- Exclude credential stores, secret manifests, encrypted-secret outputs, and platform-specific secret contexts by default.
- Require explicit user authorization before accessing known secret-bearing files or locations.
- Restrict inspection to the user-approved project root and reject path traversal, symlink escapes, and unrelated host configuration.
- Add an output policy prohibiting secret values from appearing in reports, diagnostics, prompts, or retained artifacts.
- Document that only the existence and names of environment variables are required for this analysis.
