T09 · Insecure Skill Coding Practices
- Location
scripts/ci_autopsy.py:45- Finding
Raw GitHub Actions Logs Are Exposed Without Secret Redaction
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ci_autopsy.py, lines 45–53
Vulnerability Type: Sensitive information exposure through unredacted CI logs
Risk Level: MediumVulnerable Code
python def cmd_failed_logs(args: argparse.Namespace) -> None: out = run([ gh_bin(), "run", "view", str(args.run_id), "--repo", args.repo, "--log-failed", ]) print(out)Technical Analysis
The
failed-logscommand retrieves complete failed-job logs through the authenticated GitHub CLI and writes them directly to standard output. No redaction, structured filtering, output-size restriction, or manual review boundary is applied beforeprint(out).This implementation conflicts with the security requirements in
SKILL.md, which state that tokens must never be printed and secrets in logs must be redacted before quotation. GitHub masks registered secrets in many circumstances, but that protection is not comprehensive. Logs may still contain unregistered credentials, transformed secrets, authorization headers, signed URLs, private keys, personal data, or values printed by compromised dependencies.Repository and run identifiers are passed to
subprocess.runas separate arguments rather than through a shell, so this code does not establish command injection. The flaw is specifically the unrestricted disclosure of remotely retrieved log content.Attack Path
- A workflow step, malicious contributor, or compromised dependency writes a sensitive value into a failing job's output.
- The value is not recognized or masked by GitHub, such as when it is transformed, dynamically generated, or not registered as a repository secret.
- A user or agent invokes:
bash python3 scripts/ci_autopsy.py failed-logs --repo owner/repo --run-id 123 - The script uses the locally authenticated
ghclient to retrieve the failed-job logs. - The complete response ...[truncated 996 chars]
- Remediation
View remediation
Remediation Suggestions
- Sanitize all retrieved logs before printing them. Redact common GitHub, cloud-provider, bearer-token, authorization-header, URL-credential, private-key, and password patterns.
- Support user-configured secret values and replace exact matches with a fixed marker such as
[REDACTED]. - Extract only short excerpts surrounding relevant errors instead of emitting complete failed-job logs.
- Add strict output-length and line-count limits, with an explicit opt-in mechanism for reviewing additional content.
- Warn users that heuristic redaction cannot guarantee removal of every secret and require confirmation before exposing raw logs.
- Keep raw log data out of exception messages, persistent files, telemetry, and agent transcripts wherever possible.
- Add automated tests using representative GitHub tokens, cloud credentials, bearer headers, signed URLs, private-key blocks, transformed secrets, and ordinary non-secret text to detect both redaction failures and excessive false positives.
- Continue using minimally scoped GitHub credentials. Read-only analysis should use only repository and Actions read permissions; write permissions should be enabled solely for explicitly approved PR operations.
