T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:51- Finding
Unnecessary Access to Secret-Bearing Environment Files
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 51
Vulnerability Type: Excessive access to sensitive configuration
Risk Level: MediumVulnerable Code
markdown 6. **Environment variables** — scan `.env`, `.env.local`, `.env.example` for required varsTechnical Analysis
The skill instructs the agent to scan
.envand.env.local, which commonly contain live database passwords, API keys, signing secrets, access tokens, and cloud credentials. Reading the values of these files is not necessary when the task only requires determining which environment variable names must appear in generated configuration.This violates least-privilege principles by exposing sensitive values to the agent context when
.env.example, application manifests, or key-only parsing would normally provide sufficient information. Once loaded, secret values may be included in conversation context, diagnostics, generated output, or platform logs. The audited instruction does not explicitly direct the agent to exfiltrate these values.Attack Path
- A user invokes the skill on a project containing production credentials in
.envor.env.local. - The agent follows the instruction to scan those files.
- The complete secret values are loaded into the agent or tool context.
- Values may subsequently be exposed through generated content, debugging output, telemetry, logs, or accidental context disclosure.
Impact Assessment
Exposure is limited to secrets present in the environment files the executing user can already access. Depending on those credentials, compromise could extend to databases, third-party APIs, cloud resources, session-signing systems, or other production services. This instruction does not independently grant filesystem privileges or bypass operating-system access controls.
- A user invokes the skill on a project containing production credentials in
- Remediation
View remediation
Remediation Suggestions
- Inspect
.env.exampleby default rather than live.envfiles. - Derive required variable names from manifests, source references, and existing Compose configuration.
- Request explicit user authorization before reading
.envor.env.local. - If access is authorized, extract only variable names and never return, log, or retain their values.
- Apply automatic redaction to values associated with keys containing terms such as
PASSWORD,SECRET,TOKEN,KEY, orCREDENTIAL. - Document that production environment files should remain outside agent context unless their contents are indispensable to the requested task.
- Inspect
