T09 · Insecure Skill Coding Practices
- Location
README.md:68- Finding
Bearer Token Stored in a Plaintext File Without Explicit Access Controls
- Content
View full analysis
~/.config/env/global.env ``` ### Technical Analysis The setup instructions persist an X bearer token in `~/.config/env/global.env` using ordinary shell redirection. Neither the directory nor the resulting file is assigned an explicit restrictive permission mode. The effective permissions therefore depend on the operator's current `umask`. On systems using a permissive configuration, the credential file may be readable by other local users, services, backup agents, indexing tools, or processes running under a shared account. The token is legitimately required for the Skill's X search and read operations. The security issue is not its use against X, but its unprotected persistence in a general-purpose plaintext configuration file. The documented command may also encourage users to place a real token directly into an interactive shell command, potentially leaving it in shell history. ### Attack Path 1. An operator follows the documented setup instructions and writes a valid X bearer token to `~/.config/env/global.env`. 2. The file is created under the operator's default `umask` without an explicit `0600` mode. 3. A local user, compromised process, backup service, or other component with access to the home directory reads the file. 4. The attacker extracts `X_BEARER_TOKEN`. 5. The attacker submits the token to X API endpoints and exercises the API permissions associated with that credential until it is revoked or expires. This path requires local filesystem access or access through another service that can read the file; the project does not itself transmit the token to an unauthorized host. ### Impact Assessment A successful attacker can obtain the ...[truncated 646 chars]- Remediation
View remediation
"$HOME/.config/env/global.env" ``` 3. Verify the permissions after creation: ```bash chmod 700 "$HOME/.config/env" chmod 600 "$HOME/.config/env/global.env" ``` 4. Avoid entering real secrets directly into commands retained by shell history. Prefer a hidden prompt, secret-manager injection, or a protected editor. 5. Ensure the credential file is excluded from source control, diagnostics, backups that lack encryption, and application logs. 6. Grant the token only the minimum X API scopes needed for searching and reading. 7. Document token rotation and immediate revocation procedures for suspected disclosure. ]]>
