T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:246- Finding
Detected secrets can be disclosed through incomplete output redaction
- Content
View full analysis
Vulnerability Details
File Location:
scripts/main.py, lines 210-215, 246, and 372
Vulnerability Type: Incomplete sensitive-data redaction
Risk Level: HighVulnerable Code
python PATTERNS = [ (r'AKIA[0-9A-Z]{16}', 'AWS Access Key ID'), (r'aws_secret_access_key\s*=\s*["\']?[A-Za-z0-9/+=]{40}["\']?', 'AWS Secret Key'), (r'ghp_[A-Za-z0-9]{36}', 'GitHub Personal Access Token'), (r'sk-[A-Za-z0-9]{20,}', 'OpenAI/Stripe API Key'), (r'private[_-]?key\s*[=:]\s*["\']?-----BEGIN', 'Private Key'), (r'database[_-]?url\s*[=:]\s*["\']?\w+://[^:]+:[^@]+@', 'Database URL with credentials'), ]python # Mask the secret masked = re.sub(r'["\'][^"\']{10,}["\']', '"***MASKED***"', line.strip()) findings.append({ 'line': i, 'type': secret_type, 'content': masked, 'severity': 'critical' })python for secret in secrets: print(f" Line {secret['line']}: {secret['type']}") print(f" {secret['content']}")Technical Analysis
The detector recognizes several credentials that do not need to be enclosed in quotation marks, including AWS access key IDs, GitHub personal access tokens, OpenAI or Stripe keys, unquoted AWS secret keys, and credentials embedded in database URLs.
The redaction expression only replaces a sequence of at least ten characters surrounded by matching quote-like delimiters. Consequently, an unquoted secret can be successfully detected but remain unchanged in
secret['content']. The program subsequently prints that content directly.This is especially dangerous for a security scanner because its output is likely to be retained in CI logs, terminal recordings, support bundles, or audit artifacts.
Attack Path
- A repository or scanned directory contains a credential in a supported but unquoted format, such as an unquoted
ghp_...token or AWS access key. - A user or CI job invokes `python3 script ...[truncated 1025 chars]
- A repository or scanned directory contains a credential in a supported but unquoted format, such as an unquoted
- Remediation
View remediation
Remediation Suggestions
- Do not print source lines containing detected credentials. Report only the file path, line number, credential type, and a non-sensitive fingerprint if correlation is required.
- If a preview is necessary, redact the exact match produced by the credential-specific pattern rather than searching for an independently quoted value.
- Use
re.sub()with the active detection pattern or preserve the match span and replace that exact character range with***MASKED***. - For database URLs, parse and replace the password and other sensitive components before rendering any output.
- Avoid retaining plaintext secret-bearing lines in the finding structure.
- Add automated tests covering quoted and unquoted variants of every supported credential format.
- Configure CI systems to restrict access to historical scanner logs and remove existing logs that may contain exposed credentials.
- Rotate any real credentials that have already appeared in scanner output.
