T09 · Insecure Skill Coding Practices
- Location
SKILL.md:44- Finding
Potential Public Disclosure of Sensitive Agent Configuration
- Content
View full analysis
/ ├── SKILL.md ├── _meta.json └── references/ ├── soul.md ├── agents.md ├── identity.md └── tools.md ``` ```bash gh repo create / \ --public \ --description "" \ --source \ --push cd git add -A git commit -m "v: " git push origin master ``` The packaging instructions specify that `references/soul.md` contains the complete `SOUL.md` file. The adjacent entries similarly package `AGENTS.md`, `IDENTITY.md`, and `TOOLS.md`. ### Technical Analysis The workflow copies complete Agent configuration files into a publication directory and then publishes that directory to ClawHub and GitHub. When creating a GitHub repository, it explicitly selects public visibility through `--public`. For existing repositories, `git add -A` stages every tracked and untracked change under the Skill directory without applying a file allowlist. Agent configuration files may contain private operating instructions, internal tool details, filesystem paths, private endpoints, user information, or credentials accidentally embedded during development. The workflow does not require secret scanning, sensitive-content review, an explicit file manifest, repository-visibility verification, or inspection of the staged Git diff before publication. Although the Skill asks whether publication should occur, that general confirmation does not communicate which files will become public or require separate approval for public repository visibility. Once pushed, sensitive information may remain recoverable from Git history even if it is removed in a later commit. ### Attack Path 1. A developer or Agent writes sensitive information into `SOUL.md`, `AGE ...[truncated 1483 chars]- Remediation
View remediation
