T09 · Insecure Skill Coding Practices
- Location
SKILL.md:67- Finding
Reusable Access Credentials Sent Through Email
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 67
Vulnerability Type: Plaintext transmission of sensitive authentication data
Risk Level: MediumVulnerable Code Snippet:
markdown - **Day 0:** Welcome email + access credentials + kickoff questionnaireTechnical Analysis
The documented onboarding workflow explicitly instructs the agent to include access credentials in a welcome email. Conventional email does not provide a suitable end-to-end secret-delivery mechanism. Credential-bearing messages can persist in sender and recipient mailboxes, email-provider storage, backups, forwarding chains, notification previews, and mail-processing logs.
The workflow does not require the credentials to be single-use, time-limited, encrypted for the intended recipient, or invalidated after first use. It also does not require a forced password reset or multifactor authentication. Consequently, anyone who obtains the message may be able to reuse the credentials.
Attack Path
- The onboarding workflow creates or obtains credentials for a client resource.
- The agent sends those credentials in the Day 0 welcome email.
- The message is retained in one or more mail systems or is forwarded to another account.
- An attacker gains access to the recipient's mailbox, a forwarded copy, an email archive, or exposed mail-processing records.
- The attacker extracts the reusable credentials.
- The attacker authenticates to the associated account or project resource before the credentials are revoked.
Impact Assessment
Successful exploitation could permit unauthorized access with the privileges assigned to the exposed client account. Depending on the destination system, this may expose client documents, project data, communications, or account functionality. The precise scope is not defined by the repository and therefore depends on the permissions granted to the transmitted credentials.
- Remediation
View remediation
Remediation Suggestions
- Do not send passwords, API keys, access tokens, or other reusable credentials through email.
- Replace credential delivery with a cryptographically random, single-use account-activation link.
- Apply a short expiration period to the activation token and invalidate it immediately after use.
- Bind activation to the intended account and prevent token reuse.
- Require the client to establish their own password through a secure HTTPS page.
- Enforce multifactor authentication where supported.
- Avoid placing activation tokens in email subject lines or analytics-enabled links, and redact them from application and proxy logs.
- Revoke any provisioned credential if activation is not completed within the permitted period.
- Add documented recovery and immediate revocation procedures for misdirected or compromised onboarding messages.
