T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:145- Finding
Centralized Credential File Can Be Read and Disclosed Through Agent Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 145-151; related mandatory access directives at lines 30 and 113
Vulnerability Type: Excessive credential access and plaintext secret disclosure
Risk Level: High
Category: T05: Unauthorized Access and Privilege EscalationVulnerable Code
bash # Check token exists grep SERVICE_TOKEN ~/Documents/life/.env # List all tokens cat ~/Documents/life/.envThe broader workflow also mandates access to the centralized file:
markdown **ALWAYS check `~/Documents/life/.env` FIRST before asking for tokens!**Technical Analysis
The Skill directs the Agent to access a centralized
.envfile that may contain credentials for many unrelated services. Thegrepcommand prints the selected environment-variable assignment, including its secret value. More critically,catprints every credential in the file.In an Agent environment, command output may be returned to the caller, retained in conversation history, or captured by execution and observability logs. Merely determining whether a token exists does not require revealing its value, and checking for one service does not require reading or printing credentials belonging to other services. The mandatory instruction therefore violates least-privilege principles and creates an avoidable disclosure channel.
Attack Path
- A caller requests API access or asks the Agent to check whether a service token exists.
- The Skill instructs the Agent to inspect
~/Documents/life/.envbefore requesting credentials. - The Agent runs the documented
grepcommand or the broadercatcommand. - One credential or the entire credential collection is written to stdout.
- The caller, conversation transcript, tool-output recorder, or logging system captures the plaintext secrets.
- An attacker uses the exposed tokens against their corresponding external services within the permissions g ...[truncated 713 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
cat ~/Documents/life/.envinstruction entirely. - Replace output-producing checks with a parser that returns only a boolean presence result and never prints the secret value.
- Restrict each invocation to an explicitly allowlisted environment-variable name associated with the requested service.
- Require explicit user authorization before accessing credential storage.
- Prefer an operating-system keychain or dedicated secret manager with per-secret access controls and audit logging.
- Redact credentials from command output, exceptions, transcripts, and telemetry.
- Do not pass secrets through shell command lines where they may enter process or shell history.
- Add guidance prohibiting disclosure of credential values unless the user explicitly requests it and the output channel is confirmed secure.
- Remove the
