T09 · Insecure Skill Coding Practices
- Location
SKILL.md:28- Finding
Skill instructions encourage disclosure of an API key through chat
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:28-31
Vulnerability Type: Credential exposure through an insecure communication channel
Risk Level: MediumVulnerable Code
markdown Before running, check the `BROWSERACT_API_KEY` environment variable. If not set, do not take other measures; ask and wait for the user to provide it. **Agent must inform the user**: > "Since you haven't configured the BrowserAct API Key, please visit the [BrowserAct Console](https://www.browseract.com/reception/integrations) to get your Key."Technical Analysis
The documentation instructs the agent to ask the user to provide the
BROWSERACT_API_KEYwhen it is not configured. API keys are authentication credentials and should not be entered into conversational interfaces. Chat content may be retained in conversation history, application logs, telemetry, or agent context and may be visible to parties that would not otherwise have access to the user's local secret store.The script legitimately needs this credential to authenticate with the declared BrowserAct HTTPS API. However, obtaining the key through chat is unnecessary because the implementation already supports reading it from the
BROWSERACT_API_KEYenvironment variable. The network transmission tohttps://api.browseract.comis consistent with the Skill's documented functionality; the identified weakness is the credential acquisition guidance rather than the declared API request itself.Attack Path
- A user invokes the Skill without configuring
BROWSERACT_API_KEY. - The agent follows
SKILL.mdand asks the user to provide the key. - The user posts the BrowserAct API key in the conversation.
- The credential becomes part of chat history, logs, telemetry, or retained agent context.
- A party with access to one of those surfaces obtains the key.
- The exposed key is reused against BrowserAct services until it is revoked or expires.
I
...[truncated 440 chars]
- A user invokes the Skill without configuring
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to ask users to provide API keys through chat.
- Instruct users to configure
BROWSERACT_API_KEYlocally using an environment variable or an approved secret manager. - Ensure the agent only checks whether the variable exists and never prints, echoes, stores, or requests its value.
- Add explicit guidance stating that API keys must not be pasted into conversations.
- Recommend immediate key revocation and rotation if a credential has already been shared through chat.
- Where supported, use narrowly scoped credentials with quota limits and short expiration periods.
