T09 · Insecure Skill Coding Practices
- Location
scripts/common.py:214- Finding
AgentBay API Key Exposed in Plaintext Logs
- Content
View full analysis
- Remediation
View remediation
= 8 else "[REDACTED]" _log.info("AgentBay credential loaded: %s", masked_key) ``` Complete omission is preferable to masking. 3. Add a centralized logging filter that redacts known secret values and sensitive field names such as `api_key`, `authorization`, `token`, `password`, and `cookie`. 4. Rotate every AgentBay API key used while the vulnerable code was active. Rotation is necessary because deleting logs does not invalidate credentials that may already have been copied. 5. Securely remove existing local logs and investigate whether console output or logs were forwarded to CI/CD systems, support archives, backups, or centralized logging platforms. 6. Restrict log-file permissions to the account executing the skill and reduce retention periods. 7. Add automated tests and secret-scanning checks that fail when credentials or sensitive configuration values appear in log output. ]]>
