T09 · Insecure Skill Coding Practices
- Location
SKILL.md:92- Finding
API Credentials May Be Disclosed Through the Agent Conversation
- Content
View full analysis
/account/my-api`) and either provides `AK/SK/PP` to you or re-runs `okx config init` themselves. ``` ### Technical Analysis The instruction explicitly allows a user to provide the OKX API key, secret key, and passphrase (`AK/SK/PP`) directly to the Agent. These values are sensitive authentication credentials and should not be transmitted through a conversational interface. Credentials submitted this way can become part of the Agent context, conversation history, provider telemetry, debugging traces, or tool logs. The document already identifies `okx config init` as a local credential-entry mechanism, making disclosure to the Agent unnecessary. The actual permissions available to an attacker depend on the permissions assigned to the exposed API key. A read-only key may expose account, balance, position, and transaction information. A key with trading permissions may allow unauthorized orders or account-position changes. Any additional permissions granted to the key would increase the potential impact. ### Attack Path 1. A user encounters an invalid API key and follows the replacement instructions. 2. The user chooses the documented option to provide `AK/SK/PP` to the Agent. 3. The API key, secret key, and passphrase enter the conversation and Agent context. 4. The credentials may be retained in chat history, application logs, telemetry, support exports, or other intermediate systems. 5. A party or compromised component with access to those records obtains the credentials. 6. The exposed credentials are used to authenticate to OKX within the API key's configured permissions. ### Impact Assessment Successful exploitation could expose private account ...[truncated 401 chars]- Remediation
View remediation
