T09 · Insecure Skill Coding Practices
- Location
SKILL.md:10- Finding
Plaintext API Key Storage Without Required File Permission Controls
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10–31
Vulnerability Type: Plaintext credential storage with insufficient permission requirements
Risk Level: MediumVulnerable Code
markdown **Base URL:** Read from `~/.config/looki/credentials.json` → `base_url` field. If the file does not exist, ask the user for both `base_url` and `api_key`. **Security:** - Before first use, validate the `base_url` by sending a GET request to `https://open.looki.ai/api/v1/verify?endpoint={base_url}`. Do not include the API key in this request. If validation fails, inform the user and do not proceed. - Only send the API key in the `X-API-Key` header to `{base_url}/*` endpoints. Do not send it to any other domain. - Do not save the API key to agent memory, chat history, or any location other than `~/.config/looki/credentials.json`. ## Setup **Credentials file:** `~/.config/looki/credentials.json` On first use, check if this file exists. If it does, read `base_url` and `api_key` from it. If it does not, ask the user for both values and offer to save them to this file. ```json { "base_url": "<YOUR_BASE_URL>", "api_key": "<YOUR_API_KEY>" }base_url— The API endpoint URL provided by the user. Do not assume a default; always ask the user if not already saved.api_key— The user's Looki API key, starting withlk-.
Credentials should only be stored in this file. Do not save the API key to agent memory, environment variables, or any other persistent storage.
text ### Technical Analysis The Skill instructs the Agent to persist the Looki API key as plaintext JSON in `~/.config/looki/credentials.json`, but it does not require owner-only permissions for either the containing directory or the file. The actual access mode may therefore depend on the Agent's file-writing implementation and the process umask. If the file is created with overly broad permissions, another local account or process may read the API key. The ...[truncated 2306 chars]- Remediation
View remediation
Remediation Suggestions
- Require creation of
~/.config/lookiwith owner-only permissions (0700). - Create
credentials.jsonatomically with mode0600, rather than relying on the process umask. - Refuse to read a credentials file that is group-readable, world-readable, owned by another user, or not a regular file.
- Reject symbolic links for both the credentials file and relevant parent path components.
- Write credentials through a securely created temporary file in the same protected directory, set its permissions, flush it, and atomically rename it into place.
- Prefer an operating-system credential manager or secret store when available, retaining the file only as a documented fallback.
- Avoid printing the key in commands, logs, diagnostics, errors, or tool-call transcripts.
- Preserve the existing controls that validate
base_urlwithout the key and restrictX-API-Keytransmission to the validated endpoint. - Document API-key rotation and revocation procedures for suspected exposure.
- Require creation of
