T09 · Insecure Skill Coding Practices
- Location
SKILL.md:41- Finding
Wallet-Control JWT Persisted in a Repository File
- Content
View full analysis
"`. If the user successfully logged in, it will return `{"status": "completed", "token": "ey..."}`. 4. **Persist the Token**: Save this `token` into your local `config.json` as your authentication credential for all future requests. ``` The credential is subsequently used as a bearer token: ```markdown All requests to the Proxy Service require an authorization token (JWT). You should retrieve the assigned Auth Token from your configuration (e.g. `config.json` or `$UNIBASE_PROXY_AUTH`). Attach the token to your proxy requests: ``` Authorization: Bearer Content-Type: application/json ``` ``` ### Technical Analysis The Skill instructs the agent to save a bearer JWT in `config.json` inside the repository. This is sensitive authorization material because it is used to access the user's automatically provisioned wallets and invoke the wallet RPC endpoint. ...[truncated 2252 chars]- Remediation
View remediation
