T09 · Insecure Skill Coding Practices
- Location
prompts/sources/discord.md:12- Finding
Discord session token exposed to an unverified third-party exporter and command-line arguments
- Content
View full analysis
-c -f Json ``` ``` ### Technical Analysis The Skill instructs users to retrieve a live Discord authorization token from browser developer tools and disclose it to a community-maintained exporter. This token is a bearer credential: any process or person obtaining it may be able to act with the authenticated account's access until the token is revoked or expires. The CLI example places the token directly in a command-line argument. Depending on the operating system and shell configuration, it may consequently appear in: - Shell history files. - Process listings and process-monitoring tools. - Terminal recordings, screenshots, or support logs. - Audit or endpoint-monitoring telemetry. - Crash reports generated by the exporter. The recommended executable is downloaded from a mutable third-party release channel without a pinned version, checksum, signature-verification procedure, or sandboxing requirement. A compromised release could read and transmit the supplied token and any exported messages. The operation exceeds minimum privilege because converting an existing JSON or CSV file to HTML does not require the Skill itself to obtain or handle a reusable account credential. ### Attack Path 1. A user asks the Agent to convert a Discord channel without supplying ...[truncated 1036 chars]- Remediation
View remediation
