T09 · Insecure Skill Coding Practices
- Location
SKILL.md:30- Finding
Qiniu SecretKey Exposed Through Command-Line Arguments
- Content
View full analysis
``` ``` ### Technical Analysis The Skill instructs users to pass a long-lived Qiniu AccessKey and SecretKey directly as command-line arguments. Depending on the operating system and shell configuration, these values may be: - Recorded in plaintext shell history. - Temporarily visible through process-inspection facilities while `qshell` is running. - Captured by terminal logging, command auditing, telemetry, or diagnostic tools. - Disclosed if the user pastes the completed command into chat or support records. The network transmission of Qiniu credentials is necessary for authenticated storage management, but exposing the SecretKey through a command-line interface is not the minimum-risk method of collecting that credential. ### Attack Path 1. A user follows the authentication instructions and replaces `` with a valid Qiniu SecretKey. 2. The shell records the complete command in its history, or a local monitoring facility captures the process arguments. 3. An attacker with access to the user's account, history files, terminal logs, audit records, or applicable process-inspection interface retrieves the SecretKey. 4. The attacker configures another `qshell` instance or directly invokes Qiniu APIs with the compromised credentials. 5. The attacker performs any operation authorized by the associated Qiniu key. This path requires access to local history, logs, process metadata, or another location where the completed command was recorded. The Skill does not itself transmit the key to an unrelated third party. ### Impact Assessment Compromise could expose the Qiniu account resources permitted by the ...[truncated 512 chars]- Remediation
View remediation
