T09 · Insecure Skill Coding Practices
- Location
scripts/env_toolkit.py:31- Finding
Protective quoting is removed before environment values are serialized
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly does what it claims, but it handles secret-bearing .env files and can write or display sensitive values with unsafe serialization behavior.
Review this before installing if you use .env files containing production secrets. Avoid `--with-values` and `--keep-values` unless you are working locally in a controlled context, do not commit generated files that preserve real values, and do not source merged or generated env files in shell workflows unless their contents have been reviewed and safely quoted.
scripts/env_toolkit.py:31Protective quoting is removed before environment values are serialized
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: env-file-toolkit
description: Manage .env files with validate, diff, template generation, merge, and missing-key checks. Use when working with environment variable files, comparing .env.local vs .env.production, generating .env.example templates, validating .env syntax, merging env files, or checking for missing environment variables.
---
# Env File Toolkit
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: env-file-toolkit
description: Manage .env files with validate, diff, template generation, merge, and missing-key checks. Use when working with environment variable files, comparing .env.local vs .env.production, generating .env.example templates, validating .env syntax, merging env files, or checking for missing environment variables.
---
# Env File Toolkit
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: env-file-toolkit
description: Manage .env files with validate, diff, template generation, merge, and missing-key checks. Use when working with environment variable files, comparing .env.local vs .env.production, generating .env.example templates, validating .env syntax, merging env files, or checking for missing environment variables.
---
# Env File Toolkit
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Compare two .env files — shows keys only in one file and changed values:
python3 scripts/env_toolkit.py diff .env.local .env.production
The documented template .env --keep-values command explicitly preserves actual secret values when generating a template-like artifact. This creates a real risk of credential disclosure through copied example files, terminal history, shared outputs, or accidental commits, making the credential-access concern substantive here rather than a mere filename mention.
python3 scripts/env_toolkit.py template .env
python3 scripts/env_toolkit.py template .env -o .env.example
python3 scripts/env_toolkit.py template .env --keep-values # keep actual values
The list-keys .env --with-values example explicitly instructs displaying environment variable values, which may include secrets such as API keys and passwords. This turns a benign inspection feature into a concrete secret-exposure risk via console output, logs, screenshots, or agent responses.
python3 scripts/env_toolkit.py list-keys .env
python3 scripts/env_toolkit.py list-keys .env --with-values
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#!/usr/bin/env python3
"""Toolkit for .env file management.
Commands: validate, diff, template, merge, list-keys, check-missing.
"""
No suspicious patterns detected.