T09 · Insecure Skill Coding Practices
- Location
scripts/context-migrator.py:1045- Finding
Private Signing Key Created Before Secure Permissions Are Enforced
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed offline migration tool for AI-agent settings, with sensitive local file access that fits its purpose and one optional signing-key hardening issue.
Install only if you want an offline tool that can read and migrate AI-agent skills, rules, and MCP settings. Review generated plans before using --yes, prefer plan-only/dry-run first, and avoid using bundle-keygen on shared systems until its private-key creation is hardened.
scripts/context-migrator.py:1045Private Signing Key Created Before Secure Permissions Are Enforced
The declared description promises a broad context migration and backup system across multiple AI coding tools, with safety and validation features. The supplied code chunk, however, is only a module docstring describing a lightweight detection probe framework that checks local product/profile installation state. Detection may be a supporting component of a migration tool, but in isolation this chunk does not implement or demonstrate the declared primary capabilities. Therefore the description materially overstates what this code actually does.
The description promises a context migration and management capability across AI coding agents, including sophisticated operations like backup/restore, secret redaction, preview, verification, and rollback. In contrast, this code chunk is a detector module whose purpose is to identify whether certain products/profiles are installed or configured on the local machine. It inspects local binaries, files, directories, home/workspace paths, and macOS app bundles, and may invoke local commands like version checks and mdfind. While such detection could be a supporting component of a migration tool, this chunk by itself does not implement the declared core functionality and instead exposes an undeclared capability: environment/product detection. Therefore the supplied code does not accurately represent the declared purpose.
The declared description presents a high-level migration and backup tool for AI-coding-agent context across products. The supplied code does not perform any migration, backup, restore, comparison, movement of context, secret handling, or rollback. Instead, it is a narrow internal utility for resolving registry selector aliases and default profiles. This is a materially different primary purpose, so the description does not accurately represent the code chunk.
There is a clear description-behavior mismatch based on the provided code chunk. The declaration describes a broad tool for migrating and managing AI-agent context across multiple products, with redaction and rollback features. The actual code shown does not implement those workflows; it only exposes a CLI entry point for a secret scanner. While secret scanning could support redaction in a larger system, this chunk's observable behavior is materially narrower and different from the declared primary purpose.
The declared description promises a broad context portability tool for multiple AI agent environments, including migration, backup, restore, comparison, redaction, verification, and rollback. The supplied code does none of that. Instead, it inspects files in a single directory tree for likely hardcoded secrets, private keys, connection-string credentials, and symlinks that are absolute or escape the root. While secret redaction/safety is mentioned in the description, this code only detects and rejects potential secrets; it does not migrate or manage context artifacts. Therefore the actual behavior is materially narrower and different in primary purpose from the declared description.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
{
"antigravity": {
"global_skills": "~/.gemini/config/skills",
"project_skills": ".agents/skills",
"rules": ".agents/rules",
"mcp": "~/.gemini/config/mcp_config.json",
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
{
"antigravity": {
"global_skills": "~/.gemini/config/skills",
"project_skills": ".agents/skills",
"rules": ".agents/rules",
"mcp": "~/.gemini/config/mcp_config.json",
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
{
"antigravity": {
"global_skills": "~/.gemini/config/skills",
"project_skills": ".agents/skills",
"rules": ".agents/rules",
"mcp": "~/.gemini/config/mcp_config.json",
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
{
"antigravity": {
"global_skills": "~/.gemini/config/skills",
"project_skills": ".agents/skills",
"rules": ".agents/rules",
"mcp": "~/.gemini/config/mcp_config.json",
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
{
"antigravity": {
"global_skills": "~/.gemini/config/skills",
"project_skills": ".agents/skills",
"rules": ".agents/rules",
"mcp": "~/.gemini/config/mcp_config.json",
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
{
"antigravity": {
"global_skills": "~/.gemini/config/skills",
"project_skills": ".agents/skills",
"rules": ".agents/rules",
"mcp": "~/.gemini/config/mcp_config.json",
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
{
"antigravity": {
"global_skills": "~/.gemini/config/skills",
"project_skills": ".agents/skills",
"rules": ".agents/rules",
"mcp": "~/.gemini/config/mcp_config.json",
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
{
"antigravity": {
"global_skills": "~/.gemini/config/skills",
"project_skills": ".agents/skills",
"rules": ".agents/rules",
"mcp": "~/.gemini/config/mcp_config.json",
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
{
"antigravity": {
"global_skills": "~/.gemini/config/skills",
"project_skills": ".agents/skills",
"rules": ".agents/rules",
"mcp": "~/.gemini/config/mcp_config.json",
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| MCP | `~/.claude.json` |
| Project MCP | `.mcp.json` |
| Project config | `.claude/settings.json` |
| Config | `~/.claude/settings.json` |
<!-- END GENERATED: ide-paths.json summary -->
- Settings include project `.claude/settings.json` and local `.claude/settings.local.json`; local scopes are manual.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| MCP | `~/.claude.json` |
| Project MCP | `.mcp.json` |
| Project config | `.claude/settings.json` |
| Config | `~/.claude/settings.json` |
<!-- END GENERATED: ide-paths.json summary -->
- Settings include project `.claude/settings.json` and local `.claude/settings.local.json`; local scopes are manual.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| MCP | `~/.claude.json` |
| Project MCP | `.mcp.json` |
| Project config | `.claude/settings.json` |
| Config | `~/.claude/settings.json` |
<!-- END GENERATED: ide-paths.json summary -->
- Settings include project `.claude/settings.json` and local `.claude/settings.local.json`; local scopes are manual.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| MCP | `~/.claude.json` |
| Project MCP | `.mcp.json` |
| Project config | `.claude/settings.json` |
| Config | `~/.claude/settings.json` |
<!-- END GENERATED: ide-paths.json summary -->
- Settings include project `.claude/settings.json` and local `.claude/settings.local.json`; local scopes are manual.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |
No suspicious patterns detected.