T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:52- Finding
Mandatory Credential Inspection May Expose API Keys to Agent-Visible Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 52–63
Vulnerability Type: Excessive access to sensitive credential configuration
Risk Level: HighVulnerable Code
markdown ### Step A — Verify credentials Run **both** commands — the `apiKey` field from `okx auth status --json` is the auth-binary's internal state and is always `false` regardless of whether `~/.okx/config.toml` has an API-key profile. `okx config show --json` is the only authoritative source for API-key presence. ```bash okx config show --json # reveals API-key profiles (TOML config) okx auth status --json # reveals OAuth session state (auth-binary state)Apply in this order — first match wins:
config show --jsonhas any profile with a non-emptyapi_keyfield → API Key mode. Proceed to Step B.
text ### Technical Analysis The Skill requires the agent to execute `okx config show --json` before every authenticated operation and inspect whether each profile contains a non-empty `api_key` field. According to the documentation itself, this command reveals API-key profiles sourced from `~/.okx/config.toml`. Authentication-mode detection only requires a boolean indication that credentials exist. Returning complete profile configuration violates least-privilege and data-minimization principles if the command output includes the API key or other sensitive profile attributes. Because command results are processed by the agent, exposed values may enter model-visible tool context, execution logs, telemetry, or retained conversation records. No evidence was found that the Skill intentionally transmits credentials to an external party. The vulnerability is the unnecessary exposure of credential configuration rather than confirmed exfiltration. ### Attack Path 1. A user requests any authenticated OKX operation. 2. The Skill applies its mandatory credential-check procedure. 3. The agent executes `okx confi ...[truncated 1197 chars]- Remediation
View remediation
Remediation Suggestions
- Replace
okx config show --jsonwith a dedicated authentication-status command that returns only:- Whether credentials are configured
- Authentication method
- Profile name
- Demo or live mode
- Ensure the CLI never emits API keys, secrets, passphrases, OAuth tokens, or other reusable credentials to standard output.
- Represent credential presence as a boolean such as
"api_key_configured": truerather than returning the credential field. - Redact sensitive configuration values at the CLI serialization layer, not only in the Skill's presentation logic.
- Query only the selected profile instead of enumerating every configured profile.
- Add automated tests verifying that secrets cannot appear in JSON output, terminal output, errors, debug logs, or telemetry.
- Document that agent-visible tools must not read raw credential files or return reusable authentication material.
- Recommend narrowly scoped API keys, IP allowlisting, withdrawal-disabled trading keys, and periodic key rotation as defense-in-depth controls.
- Replace
