T09 · Insecure Skill Coding Practices
- Location
SKILL.md:10- Finding
Overbroad Access to Sensitive Environment Files
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10-12
Vulnerability Type: Sensitive-data exposure through excessive file access
Risk Level: MediumVulnerable Code:
markdown 1. Detect project config surface - Check `.env`, `.env.example`, runtime defaults in source, README/SKILL docs. - Extract all Convex URLs and callback URLs.Technical Analysis
The workflow instructs the agent to inspect
.envfiles in their entirety. Such files commonly contain API keys, access tokens, passwords, and credentials unrelated to Convex. Although the guardrail atSKILL.md:41states, “Never print secrets,” it does not prevent secrets from being loaded into the agent context, retained in execution traces, or exposed to associated tooling.The instruction does not enforce key allowlisting, local parsing, value redaction, or least-privilege access. The task only requires Convex URLs and callback settings, so reading all environment-file content exceeds the access necessary to complete the stated purpose.
Attack Path
- A project contains unrelated credentials or tokens in its
.envfile. - A user invokes the skill to diagnose Convex deployment configuration.
- The workflow causes the agent to inspect the complete
.envfile. - Unrelated secrets enter the agent's processing context or tool execution records.
- Those values may consequently become accessible through logs, traces, accidental output, or downstream processing, even if the final response attempts not to print them.
Impact Assessment
The issue may expose any credentials stored in project environment files to the agent and its supporting infrastructure. The potential scope includes third-party services, databases, cloud platforms, deployment systems, or production resources associated with those credentials.
This instruction does not itself grant additional operating-system privileges or prove that secrets are exfiltrated ...[truncated 123 chars]
- A project contains unrelated credentials or tokens in its
- Remediation
View remediation
Remediation Suggestions
- Replace whole-file inspection with local parsing of an explicit allowlist of required variables, such as
CONVEX_URLand specifically documented callback URL keys. - Return only variable names, presence status, validation results, and redacted URL metadata to the agent.
- Never place complete
.envcontents or secret values into model context, command output, reports, logs, or traces. - Redact URL credentials, sensitive query parameters, fragments, tokens, and user information before analysis or display.
- Document the exact environment keys the skill is permitted to inspect.
- Require explicit user approval before examining any additional key not included in the allowlist.
- Add a guardrail stating that secret-bearing files must be parsed with a secret-safe local mechanism rather than read directly.
- Replace whole-file inspection with local parsing of an explicit allowlist of required variables, such as
