T09 · Insecure Skill Coding Practices
- Location
SKILL.md:124- Finding
API Credential Persisted to Disk and Exposed in Terminal Output
- Content
View full analysis
- Remediation
View remediation
"$BUY_FILE" API_KEY=$(jq -er '.api_key' "$BUY_FILE") export XCATCHER_API_KEY="$API_KEY" rm -f "$BUY_FILE" trap - EXIT echo "XCATCHER_API_KEY exported." ``` - Prefer an operating-system credential store or the agent platform's secret-management facility rather than a long-lived environment variable. - Ensure automation systems mask the API key if it appears in captured output. - Document credential rotation or revocation procedures for suspected exposure. - Unset the environment variable when the workflow is complete: ```bash unset XCATCHER_API_KEY API_KEY ``` ]]>
