T09 · Insecure Skill Coding Practices
- Location
SKILL.md:10- Finding
Plaintext API Key Storage in Agent-Readable Documentation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but it tells users to store and read a Gamma API key from a plaintext agent-readable file, which creates an avoidable credential exposure risk.
Install only if you are comfortable sending selected content to Gamma's API. Do not put the Gamma API key in TOOLS.md or any project document; use an environment variable or secret manager, and rotate any key that was already stored in plaintext.
SKILL.md:10Plaintext API Key Storage in Agent-Readable Documentation
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Setup
1. Get API key from https://developers.gamma.app
2. Store in environment: `export GAMMA_API_KEY=sk-gamma-xxx`
Or add to TOOLS.md: `Gamma API Key: sk-gamma-xxx`
The skill explicitly suggests placing the Gamma API key in TOOLS.md, a plaintext documentation file that may be read, indexed, or exposed during normal agent operation. This creates an avoidable credential exposure risk because secrets stored in local prompt-accessible files can leak to users, logs, or other tools.
Advising operators to store the API key in a plaintext documentation file is a real secret-handling flaw in an agent skill context. Because agent systems often inspect local files as working context, the key could be unintentionally surfaced to the model, exfiltrated in outputs, or captured in logs and version control.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST https://public-api.gamma.app/v1.0/generations \
-H "Content-Type: application/json" \
-H "X-API-KEY: $GAMMA_API_KEY" \
-d '{
Line L73 hard-codes a specific language in the natural-language example payload. This can violate language/locale policy when presented as the default behavior without telling users they can choose another language.
No suspicious patterns detected.