T09 · Insecure Skill Coding Practices
- Location
SKILL.md:260- Finding
Bot Credentials Are Stored in a Plaintext Configuration File
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:260-268
Vulnerability Type: Plaintext storage of authentication credentials
Risk Level: MediumVulnerable Code
yaml # Location: ~/.secretary/config.yaml platform: feishu tokens: feishu: "xxx" dingtalk: "xxx" wechat: "xxx"Technical Analysis
The documented configuration places Feishu, DingTalk, and WeChat bot tokens directly in a plaintext YAML file under the user's home directory. The instructions do not require restrictive file permissions, encryption, secret-manager integration, or controls preventing the file from being included in source repositories and backups.
These tokens are bearer credentials. Anyone who obtains the configuration file may be able to authenticate as the associated bot without knowing an additional password. Although the repository only contains placeholder values, following the documented configuration process would result in real credentials being stored in this format.
Attack Path
- A user follows the documented setup process and writes real bot tokens to
~/.secretary/config.yaml. - The file is created with permissive permissions, copied into a backup, included in a support archive, or accidentally committed to a repository.
- An attacker with access to that file extracts the bearer tokens.
- The attacker reuses the tokens against the relevant messaging-platform APIs.
- The attacker performs operations permitted to the compromised bot until the credentials are revoked.
Impact Assessment
Exploitation requires read access to the configuration file or a copy of it. It does not directly provide operating-system privilege escalation. The resulting platform access is limited to the permissions assigned to each compromised bot token, but may include sending messages, accessing bot-visible resources, impersonating trusted automation, or triggering workflows connected to the bot.
- A user follows the documented setup process and writes real bot tokens to
- Remediation
View remediation
Remediation Suggestions
- Store credentials in an operating-system keychain, managed secret store, or deployment-platform secret mechanism.
- Prefer references to environment variables over literal token values in YAML.
- If a local configuration file is unavoidable, create it with mode
0600and verify ownership before reading it. - Maintain a separate example file containing placeholders only.
- Add the real configuration path to version-control ignore rules.
- Prevent credentials from appearing in logs, exception messages, generated reports, and support archives.
- Document credential rotation and revocation procedures.
- Grant every bot only the minimum platform permissions necessary for its intended functions.
