T09 · Insecure Skill Coding Practices
- Location
SKILL.md:89- Finding
Reusable Device Credentials Are Printed in Plaintext
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 89–92
Vulnerability Type: Plaintext exposure of reusable authentication credentials
Risk Level: MediumVulnerable Code:
python # Save these for next time (e.g. to env or a secure store) device_data = session.auth.getDeviceData() print("Store for device login:", device_data)Technical Analysis
The documented first-time authentication example retrieves reusable Hive device credentials and prints the complete credential object to standard output. These credentials allow subsequent device login without repeating SMS-based two-factor authentication.
Printing secrets creates multiple exposure channels, including terminal history or recording, agent tool output, CI/CD logs, remote session capture, support transcripts, and other systems that collect process output. This behavior also conflicts with the project's stated policy that credentials must not be placed in prompts or logs.
Attack Path
- A user or agent follows the first-time login example in
SKILL.md. - After successful password and SMS authentication,
getDeviceData()returns reusable device authentication data. - The script prints the credential object to standard output.
- The output is retained in an agent transcript, terminal recording, CI log, or another observable output channel.
- An attacker with access to that output extracts the device group key, device key, and device password.
- The attacker uses the exposed data with the Hive username and password, if also available, to perform device login without another SMS challenge.
- The resulting session can query or control devices associated with the Hive account.
Impact Assessment
Successful exploitation may weaken the protection provided by SMS two-factor authentication and expose persistent authentication material. In combination with the account credentials required by the documented device-login fl ...[truncated 385 chars]
- A user or agent follows the first-time login example in
- Remediation
View remediation
Remediation Suggestions
- Remove the
print()statement and never emit the credential object through standard output or standard error. - Store each returned credential directly through an approved secret-store API with restrictive access controls.
- If automatic secret storage is unavailable, require the enrollment process to run in a private local TTY and provide an explicit warning before revealing any value.
- Display only redacted identifiers when diagnostic output is necessary.
- Ensure agent tool output, application logs, exception traces, and telemetry cannot serialize the credential object.
- Document credential revocation or device-registration rotation procedures for users who have already executed the example.
- Add automated checks that detect printing or logging of values returned by
getDeviceData().
- Remove the
