T09 · Insecure Skill Coding Practices
- Location
SKILL.md:73- Finding
Plaintext App Password Retrieval Without Required File-Permission Controls
- Content
View full analysis
- Remediation
View remediation
~/.config/vdirsyncer/google_app_password chmod 0600 ~/.config/vdirsyncer/google_app_password ``` 2. Prefer a vdirsyncer-supported integration with an operating-system keyring or secret manager so the password is not maintained as an ordinary plaintext file. 3. If command-based retrieval remains necessary, use a trusted absolute executable path rather than relying on `PATH` resolution: ```ini password.fetch = ["command", "/bin/cat", "~/.config/vdirsyncer/google_app_password"] ``` 4. Ensure the credential file is excluded from source control, logs, shared archives, and unencrypted backups. 5. Use an app-specific credential with the minimum server-side scope available. Do not reuse the user's primary account password. 6. Document immediate credential revocation and rotation if the file is exposed, copied, or created with unsafe permissions. ]]>
