Back to skill

Security audit

Token Management

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly about token management, but it directs agents to use a shared plaintext credential file in ways that can expose or commit all stored tokens.

Review carefully before installing. This skill should not be used as written unless you are comfortable with an agent reading and writing a shared plaintext token file, and you should remove the list-all-tokens command, avoid printing secrets, keep .env out of git, require explicit per-token approval, and prefer a real secret manager.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:145
Finding

Centralized Credential File Can Be Read and Disclosed Through Agent Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 145-151; related mandatory access directives at lines 30 and 113
Vulnerability Type: Excessive credential access and plaintext secret disclosure
Risk Level: High
Category: T05: Unauthorized Access and Privilege Escalation

Vulnerable Code

bash
# Check token exists
grep SERVICE_TOKEN ~/Documents/life/.env

# List all tokens
cat ~/Documents/life/.env

The broader workflow also mandates access to the centralized file:

markdown
**ALWAYS check `~/Documents/life/.env` FIRST before asking for tokens!**

Technical Analysis

The Skill directs the Agent to access a centralized .env file that may contain credentials for many unrelated services. The grep command prints the selected environment-variable assignment, including its secret value. More critically, cat prints every credential in the file.

In an Agent environment, command output may be returned to the caller, retained in conversation history, or captured by execution and observability logs. Merely determining whether a token exists does not require revealing its value, and checking for one service does not require reading or printing credentials belonging to other services. The mandatory instruction therefore violates least-privilege principles and creates an avoidable disclosure channel.

Attack Path

  1. A caller requests API access or asks the Agent to check whether a service token exists.
  2. The Skill instructs the Agent to inspect ~/Documents/life/.env before requesting credentials.
  3. The Agent runs the documented grep command or the broader cat command.
  4. One credential or the entire credential collection is written to stdout.
  5. The caller, conversation transcript, tool-output recorder, or logging system captures the plaintext secrets.
  6. An attacker uses the exposed tokens against their corresponding external services within the permissions g ...[truncated 713 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the cat ~/Documents/life/.env instruction entirely.
  2. Replace output-producing checks with a parser that returns only a boolean presence result and never prints the secret value.
  3. Restrict each invocation to an explicitly allowlisted environment-variable name associated with the requested service.
  4. Require explicit user authorization before accessing credential storage.
  5. Prefer an operating-system keychain or dedicated secret manager with per-secret access controls and audit logging.
  6. Redact credentials from command output, exceptions, transcripts, and telemetry.
  7. Do not pass secrets through shell command lines where they may enter process or shell history.
  8. Add guidance prohibiting disclosure of credential values unless the user explicitly requests it and the output channel is confirmed secure.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:37
Finding

Broad Git Staging Can Commit Credential Files and Unrelated Sensitive Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 37-39
Vulnerability Type: Unsafe source-control handling of secrets
Risk Level: High
Category: T09: Insecure Skill Coding Practices

Vulnerable Code

markdown
0. **Git commit (if applicable)**
   - If .env is in a git repo: `cd ~/Documents/life && git add -A && git commit -m "Before updating TOKEN_NAME"`
   - Safety first!

Technical Analysis

git add -A stages all tracked and untracked changes beneath the repository, not merely the intended token-management documentation. If .env is unignored or already tracked, this command can stage the credential file itself. It can also stage unrelated files containing private information or unfinished user changes.

Committing a secret is especially dangerous because deleting it from the working tree afterward does not remove it from existing Git objects or commit history. A later push, repository share, backup, archive, or mirror can expose the historical credential. The instruction is particularly unsafe in a workflow whose canonical credential file is located within ~/Documents/life, the same directory in which the Git operation is performed.

Attack Path

  1. ~/Documents/life is initialized as, or located inside, a Git repository.
  2. The .env file is not correctly ignored, is force-added, or was previously tracked.
  3. A token is added or changed in ~/Documents/life/.env.
  4. The Agent follows the workflow and executes git add -A.
  5. Git stages .env together with any unrelated repository changes.
  6. The subsequent commit records those secrets in repository history.
  7. The repository or its history is later pushed, shared, archived, backed up, or accessed by another collaborator.
  8. An unauthorized party extracts and uses the committed credentials.

Impact Assessment

The operation can permanently expose all credentials contained in the staged `.e ...[truncated 580 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the git add -A and automatic commit instructions from the credential workflow.
  2. Store .env outside all Git working trees or migrate credentials to a dedicated secret manager.
  3. Add .env and service-specific secret-file patterns to .gitignore.
  4. Verify that the credential file is ignored before any write operation, for example with git check-ignore.
  5. Detect whether .env is already tracked using git ls-files --error-unmatch .env; stop the workflow and warn the user if it is tracked.
  6. If a commit is necessary, stage only an explicit allowlist of non-sensitive documentation files and show the staged diff for user approval.
  7. Add pre-commit secret scanning to prevent token patterns from entering repository history.
  8. If credentials have already been committed, revoke and rotate them immediately, remove them from history with an appropriate history-rewriting tool, and coordinate cleanup of all clones and mirrors.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The skill's core design centers on storing and reusing API credentials from a plaintext .env file, which is credential access behavior by definition. In the context of a published/public skill, normalizing centralized secret retrieval from a user home directory materially raises exposure risk if the skill is invoked unexpectedly or outputs values unsafely.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: token-management
description: "Centralized API token management workflow. Store tokens in .env with expiration dates, test permissions via script battery, document capabilities in connections/, set calendar renewal reminders. Prevents re-asking for credentials, ensures token security, tracks expiration."
type: public
version: 1.0.1
status: published

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

This specific .env-related instruction couples credential storage with git commit behavior, making exposure especially severe because secrets can be preserved in repository history. If the repo is synced or shared, compromise can extend far beyond the local machine.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
### When receiving a new token:

0. **Git commit (if applicable)**
   - If .env is in a git repo: `cd ~/Documents/life && git add -A && git commit -m "Before updating TOKEN_NAME"`
   - Safety first!

1. **Ask for expiration date**

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Linking documentation to the .env variable name facilitates discovery and reuse of stored credentials. While documenting variable names is common, in this skill's broader context of centralized plaintext token storage it makes secret locations easier to enumerate and target.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
- **Expiry date:** YYYY-MM-DD
     - **Renewal link:** URL to get new token
     - How to use (code examples)
   - Link to .env variable name
   - **Example:**
     ```markdown
     ## Token Info

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The instruction to always check .env first operationalizes automatic credential retrieval from a shared plaintext store. That creates a high-risk default because the agent is told to seek stored secrets before seeking fresh user approval or narrower alternatives.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
### When needing API access:

1. **✅ ALWAYS check .env first:** `~/Documents/life/.env`
2. **If not found:** Check connections/ for setup instructions
3. **If still missing:** Ask Nicholas for token

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs the agent to inspect and even list the shared .env file without warning about credential exposure or limiting output to the minimum needed secret. Commands like cat ~/Documents/life/.env can reveal every stored token at once, turning normal use into bulk secret disclosure.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Appending tokens directly into ~/Documents/life/.env stores credentials in plaintext in a broadly accessible location. This increases risk from local compromise, accidental sharing, backups, and misuse by other tools that can read the file.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

Add token

bash
# Append to .env (skill will automate)
echo "SERVICE_TOKEN=value" >> ~/Documents/life/.env

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

Automating plaintext token insertion into .env encourages secret persistence without adequate access control, audit logging, or minimization. It also makes accidental duplication and exposure through shell history or file sync more likely.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

Add token

bash
# Append to .env (skill will automate)
echo "SERVICE_TOKEN=value" >> ~/Documents/life/.env

Check token exists

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

Using grep to check for a specific token variable is less dangerous than printing all secrets, but it still instructs direct access to the shared credential store. Depending on invocation and output handling, it may disclose sensitive names or values and reinforces unsafe secret access patterns.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

Check token exists

bash
grep SERVICE_TOKEN ~/Documents/life/.env

List all tokens

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction to list all tokens by running cat on the shared .env file is direct mass credential exposure. Any user, prompt, or downstream tool receiving that output could obtain every stored secret, enabling account compromise across multiple services.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

Running cat on the .env file exposes all stored credentials in plaintext and is one of the most dangerous instructions in the skill. This creates immediate risk of full compromise for every connected external service represented in the file.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

List all tokens

bash
cat ~/Documents/life/.env

Credential Access

High
Category
Privilege Escalation
Confidence
85% confidence
Finding

Declaring a canonical .env location in a public, shareable path standardizes where credentials live, which simplifies both legitimate access and malicious discovery. The context makes this more dangerous because the skill is published and encourages repeated reuse of the same shared secret file.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
---

## .env Location

**Canonical location:** `~/Documents/life/.env`

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The Python example shows loading secrets directly from the shared .env path, reinforcing programmatic access to plaintext credentials. In isolation this is common practice, but here it contributes to a workflow built around broad secret reuse from an insecure central file.

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

Python usage:

python
from dotenv import load_dotenv
load_dotenv('~/Documents/life/.env')  # Or absolute path

Shell usage:

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The shell example sources the entire .env and then echoes a token variable, which can expose credentials to terminal logs, process environments, and accidental copy/paste disclosure. This is an unsafe pattern for handling secrets, especially in a public skill.

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

Shell usage:

bash
source ~/Documents/life/.env
echo $YOUR_TOKEN_NAME

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill defines activation phrases in Portuguese and later instructs the agent to ask for expiration dates using Portuguese wording, imposing a language preference without opt-in. There is no statement that the skill is intended only for Portuguese-speaking users or that alternative languages are supported.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger "preciso de token Z" is broad natural language that can overlap with ordinary conversation about needing access, rather than a clearly scoped invocation phrase. The skill does not provide exclusion conditions or negative examples to distinguish when this should activate versus when the user is merely discussing tokens.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Mandating that the agent always check a shared .env store first encourages automatic retrieval and reuse of previously stored credentials without fresh user consent or scoping. In a public skill, this normalizes ambient secret access and increases the chance of unauthorized cross-task credential use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Instructing the agent to run git add/commit around .env updates is dangerous because .env commonly contains secrets, and bulk staging can capture credentials or other sensitive files into version history. Once committed, secrets may persist even if later deleted, increasing the chance of accidental publication or lateral exposure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill expands from token storage/testing into managing the user's calendar through an external CLI. That adds unrelated side effects and a second privileged integration, which could be abused to create misleading events, leak metadata about services/tokens in calendar descriptions, or normalize broader access than the skill's stated purpose requires.

Content

No source excerpt is available for this finding.