T09 · Insecure Skill Coding Practices
- Location
SKILL.md:15- Finding
Sensitive Project Credential Exposed Through a Reusable Agent URL
- Content
View full analysis
- Remediation
View remediation
`. 3. Obtain credentials through a protected secret-input or credential-store interface that prevents inclusion in model context and logs. 4. Use short-lived, single-project tokens with only the deployment permissions required for this task. 5. Ensure tokens are revocable and provide users with a clear rotation procedure. 6. Redact credentials and sensitive URL components from shell output, error messages, traces, access logs, and audit records. 7. Avoid writing authenticated commands to shell history. 8. Warn users to rotate any project key that has already been pasted into a conversation or otherwise exposed. ]]>
