T09 · Insecure Skill Coding Practices
- Location
SKILL.md:18- Finding
Plaintext API Key Disclosure Through Documented Environment Check
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 18–20
Vulnerability Type: Plaintext credential exposure
Risk Level: MediumComplete Code Snippet:
markdown 1. First check whether the environment variable `EASTMONEY_APIKEY` exists: ```bash echo $EASTMONEY_APIKEY ```Technical Analysis
The documented environment check expands and prints the complete
EASTMONEY_APIKEYvalue. This is not necessary to determine whether the variable is configured and contradicts the credential-protection statement elsewhere in the same document.Terminal output can be retained in agent transcripts, CI/CD logs, shell-session recordings, monitoring systems, screenshots, or support records. Consequently, following the documented procedure may move a secret from a protected environment variable into less-protected output channels.
The executable script itself reads the key from the environment and sends it only to the declared HTTPS endpoint; the confirmed flaw is specifically the documentation instructing users or agents to disclose the value.
Attack Path
- A user or agent configures a valid
EASTMONEY_APIKEY. - The user or agent follows
SKILL.mdand runsecho $EASTMONEY_APIKEY. - The shell expands the variable and writes the complete API key to standard output.
- The output is captured in an agent transcript, command log, CI record, terminal recording, screenshot, or another observable channel.
- An unauthorized party with access to that channel retrieves the key.
- The party reuses the credential against services that accept it, subject to the key's server-side permissions and limits.
Impact Assessment
The exposed privilege is limited to the authorization granted to the compromised Eastmoney API key. A successful attacker could potentially submit API requests as the key owner, consume quotas, generate costs if billing applies, or access any data and operations authori ...[truncated 160 chars]
- A user or agent configures a valid
- Remediation
View remediation
Remediation Suggestions
Replace the plaintext disclosure command with a presence-only test that never emits the credential:
bash if [ -n "${EASTMONEY_APIKEY:-}" ]; then echo "EASTMONEY_APIKEY is configured" else echo "EASTMONEY_APIKEY is not configured" fiAdditional hardening measures:
- Explicitly instruct users and agents never to print, log, or include the API key in model responses.
- Redact the
apikeyheader in HTTP diagnostics, exception reporting, and observability systems. - Rotate the key if it may already have appeared in logs or transcripts.
- Apply server-side least privilege, usage quotas, anomaly detection, and expiration where supported.
- Keep the credential only in a trusted secret store or protected environment variable.
