T09 · Insecure Skill Coding Practices
- Location
SKILL.md:343- Finding
API Credential Exposure Through Agent-Visible Environment Access and URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:343-359andSKILL.md:568-571
Vulnerability Type: API credential exposure and insecure secret transport
Risk Level: MediumVulnerable Skill Instructions
The following is an English translation of the relevant instructions from
SKILL.md:markdown ### API Key (two separate mechanisms; do not mix them) - Skill side: The AI reads the key from the environment variable `PANGOLINFO_API_KEY`. This is the skill's default key source. The AI reads it directly and should not repeatedly ask the user. - MCP server side: The key is supplied through MCP configuration: `--api-key=<key>`, the environment variable `PANGOLINFO_API_KEY`, `~/.pangolinfo/config.json`, hosted URL `?api_key=<key>`, or the HTTP header `Authorization: Bearer <key>`.The credential guidance is repeated in the defensive checklist:
markdown Skill-side credentials are read from `PANGOLINFO_API_KEY`. MCP-side credentials may be passed through CLI/configuration, a URL query parameter `?api_key=<key>`, or `Authorization: Bearer <key>`.Technical Analysis
The skill explicitly authorizes the AI agent itself to read
PANGOLINFO_API_KEY. This unnecessarily places a reusable API credential within the agent's accessible environment and potentially its model-visible context. An agent should normally invoke an MCP tool without receiving or processing the underlying authentication secret.The instructions also permit authentication through the URL query parameter
?api_key=<key>. Query-string credentials are unsafe because complete URLs are commonly retained by:- Reverse-proxy and web-server access logs
- Observability, tracing, and error-reporting systems
- Browser or client history
- Shell history and process invocation records
- Screenshots, copied configuration URLs, and support tickets
- Referrer propagation where the client or redirect policy permits it
Although the d ...[truncated 1679 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove agent-side secret access
- Delete the instruction directing the AI to read
PANGOLINFO_API_KEY. - Keep the credential inside the MCP server or credential broker.
- Expose only authenticated tools to the agent, never the underlying token.
- Delete the instruction directing the AI to read
-
Disallow query-string authentication
- Remove
?api_key=<key>from the documented configuration methods. - Require an
Authorization: Bearer <key>header supplied by the MCP client or secret manager outside model-visible context. - Reject query-parameter credentials server-side where compatibility permits.
- Remove
-
Apply secret redaction
- Redact JWTs and authorization headers from agent transcripts, tool errors, telemetry, traces, and access logs.
- Add detection for JWT-like three-segment values and the
api_keyparameter. - Ensure authentication errors never echo the submitted credential.
-
Use least-privilege credentials
- Issue scoped keys limited to the operations and quotas required by this skill.
- Prefer short-lived credentials where supported.
- Maintain straightforward revocation and rotation procedures.
-
Harden configuration guidance
- Recommend an operating-system secret store or MCP-specific protected configuration.
- Restrict configuration-file permissions to the owning user.
- Warn users not to paste credentials into prompts, hosted URLs, tickets, screenshots, or source-controlled files.
-
Rotate potentially exposed credentials
- Revoke and replace any key previously placed in a URL, transcript, or shared configuration.
- Review service usage and infrastructure logs for unauthorized activity.
-
