T09 · Insecure Skill Coding Practices
- Location
SKILL.md:149- Finding
API credentials exposed by unsafe troubleshooting instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 149–156
Vulnerability Type: Cleartext credential disclosure and insecure secret storage guidance
Risk Level: MediumVulnerable Code Snippet
bash # macOS / Linux: echo "XFEI_APP_ID: $XFEI_APP_ID | XFEI_API_KEY: $XFEI_API_KEY | XFEI_API_SECRET: $XFEI_API_SECRET" # Windows cmd: echo XFEI_APP_ID: %XFEI_APP_ID% ^|^| XFEI_API_KEY: %XFEI_API_KEY% ^|^| XFEI_API_SECRET: %XFEI_API_SECRET%The documentation subsequently recommends persisting an environment variable in a shell startup file:
bash echo 'export XFEI_APP_ID=your_value' >> ~/.zshrcTechnical Analysis
The troubleshooting commands expand and print the complete iFlytek API key and API secret in cleartext. Secret values displayed in a terminal may be captured by terminal scrollback, CI logs, shell-session recording, screen sharing, screenshots, support transcripts, or local monitoring software.
The nearby persistence example also establishes an unsafe pattern of storing credentials in plaintext shell startup files. Although the documented command specifically stores the application ID, users may reasonably apply the same method to the API key and secret.
This exposure is unnecessary for diagnosing whether required environment variables exist. A presence-only test provides the same diagnostic result without revealing their values.
The application implementation itself does not print these credentials. It reads them from the environment and uses them for the documented HMAC authentication flow. The vulnerability is therefore confined to the troubleshooting and credential-management instructions.
Attack Path
- A user experiences an authentication error and follows the troubleshooting instructions.
- The user runs the provided command, causing the API key and API secret to appear in cleartext.
- Terminal logging, a screen-sharing participant, a screenshot, a support transcript, a CI system, or another local ob ...[truncated 1476 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all commands that print the values of
XFEI_API_KEYorXFEI_API_SECRET. - Replace them with presence-only checks. For example:
bash for name in XFEI_APP_ID XFEI_API_KEY XFEI_API_SECRET; do if [ -n "$(printenv "$name")" ]; then echo "$name: set" else echo "$name: missing" fi done- Provide an equivalent presence-only PowerShell check:
powershell "XFEI_APP_ID", "XFEI_API_KEY", "XFEI_API_SECRET" | ForEach-Object { if (Test-Path "Env:$_") { "$_: set" } else { "$_: missing" } }- Explicitly warn users not to paste credentials into support messages, issue reports, screenshots, logs, or shared terminals.
- Recommend an operating-system credential manager, secret-management service, or permission-restricted environment file excluded from version control.
- If an environment file must be used, require restrictive filesystem permissions and provide an appropriate ignore rule. Do not recommend storing API secrets in shell startup files.
- Advise users who have already run the cleartext diagnostic command in a logged or shared environment to rotate the API key and secret and remove exposed values from retained logs where feasible.
- Remove all commands that print the values of
