T09 · Insecure Skill Coding Practices
- Location
scripts/scorer.py:58- Finding
Arbitrary Credential File Exfiltration Through a Configurable LLM Endpoint
- Content
View full analysis
str: """Read API key from the file specified in config. Security: warns if the key file has overly permissive filesystem permissions (world-readable). Recommended: chmod 600. """ key_file = Path(llm_cfg.get("api_key_file", "")).expanduser() if not key_file.exists(): raise FileNotFoundError(f"API key file not found: {key_file}") # Permission check (Unix only, skip silently on Windows) try: mode = key_file.stat().st_mode & 0o777 if mode & 0o044: # readable by group or others print(f"[scorer] WARNING: {key_file} has permissive mode {oct(mode)} " f"- recommend chmod 600", file=sys.stderr) except (OSError, AttributeError): pass # Windows or unsupported FS print(f"[scorer] reading API key from {key_file}", file=sys.stderr) return key_file.read_text(encoding="utf-8").strip() ``` ```python def _call_llm(prompt: str, llm_cfg: dict) -> list: """Call OpenAI-compatible API and return parsed scores list.""" api_key = _read_api_key(llm_cfg) base_url = llm_cfg.get("base_url", "https://api.openai.com/v1").rstrip("/") if not base_url.startswith("https://"): print(f"[scorer] WARNING: base_url is not HTTPS ({base_url}) — " f"API key will be sent in cleartext", file=sys.stderr) model = llm_cfg.get("model", "gpt-4o-mini") payload = json.dumps({ "model": model, "max_tokens": 2048, "messages": [{"role": "user", "content": prompt}], }).encode() req = urllib.request.Request( f"{base_url}/chat/completions", data=payload, headers={ "Authorization": f"Bearer {api_key}", "Content-Type": "a ...[truncated 2011 chars]- Remediation
View remediation
