T09 · Insecure Skill Coding Practices
- Location
scripts/towel-link.sh:65- Finding
GitHub Access Token Persisted in Repository Configuration
- Content
View full analysis
/dev/null) if [ -n "$TOKEN" ]; then git remote set-url origin "https://x-access-token:${TOKEN}@github.com/$ORG/$REPO_NAME.git" fi ``` ### Technical Analysis The script retrieves the active GitHub authentication token with `gh auth token` and embeds it directly into the repository's remote URL. Git stores this URL in `.git/config`, causing the credential to persist in plaintext after the script terminates. The token-bearing URL is also supplied as an argument to `git remote set-url`. Depending on operating-system process visibility and timing, another local process or user may be able to observe the token in the process argument list. Suppressing standard error does not protect the credential. Any user, process, backup system, diagnostic tool, or automation service capable of reading the repository configuration can recover it. ### Attack Path 1. A user with an authenticated GitHub CLI session invokes `towel-link.sh`. 2. The script obtains the user's active token through `gh auth token`. 3. It embeds the token in the `origin` remote URL. 4. Git writes the URL to `.git/config`. 5. An attacker, local process, backup operator, or later automation task reads the repository configuration or captures the command arguments. 6. The attacker extracts and reuses the token against GitHub. 7. The attacker gains whichever repository or organization privileges are granted to that token until it is revoked or expires. ### Impact Assessment Successful exploitation exposes the invoking user's GitHub credential. The resulting scope depends on the token's permissions and may include: - Reading private repositories - Creating, changing, or deleting repository content - Pushing malicious commits - Accessing organization resources ...[truncated 197 chars]- Remediation
View remediation
