T09 · Insecure Skill Coding Practices
- Location
templates/authenticated-session.sh:16- Finding
Authentication State Is Stored Without Enforced File Permissions
- Content
View full analysis
- Remediation
View remediation
/dev/null || true rm -f -- "$STATE_FILE" } trap cleanup EXIT ``` Persistent reuse should be explicitly requested rather than enabled by default. 6. Add comprehensive ignore rules matching all documented names: ```gitignore auth-state.json *-state.json *.auth-state.json ``` Ignore rules should supplement, not replace, filesystem permissions. 7. Set short expiration periods for reusable sessions, revoke saved sessions after CI runs, and avoid persisting sessions created after MFA unless strictly necessary. 8. Update all examples in `SKILL.md`, `references/authentication.md`, and `references/session-management.md` to demonstrate private storage and restrictive permissions. ]]>
