T09 · Insecure Skill Coding Practices
- Location
SKILL.md:56- Finding
API Credential Stored in Plaintext Configuration and Exposed in Command Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 56-69
Vulnerability Type: Plaintext sensitive credential handling
Risk Level: MediumVulnerable Code
markdown Before using, configure in TOOLS.md: ```markdown ### P-API (WhatsApp) - Base URL: https://your-server.com - API Key: your-api-key - Default Instance: instance-nametext ```bash curl -X GET "https://your-server.com/api/instances" \ -H "x-api-key: YOUR_KEY"Technical Analysis
The skill instructs users to store an API key directly in a Markdown configuration file and insert it literally into a command-line argument. It does not recommend an environment variable, protected secret store, restrictive file permissions, output redaction, or shell-history controls.
A real credential placed in
TOOLS.mdmay become accessible through local file reads, source-control mistakes, backups, diagnostic archives, agent context collection, or other processes and users with access to the workspace. Supplying the credential directly in a command can additionally expose it through shell history, command logging, debugging output, or process inspection, depending on the execution environment.The shown values are placeholders rather than embedded live credentials. The vulnerability arises from the documented credential-handling pattern that users are instructed to adopt.
Attack Path
- A user follows the documentation and places a valid P-API key and server URL in
TOOLS.md. - The configuration file, shell history, execution log, backup, or captured agent context becomes accessible to an unauthorized party.
- The unauthorized party extracts the API key and corresponding base URL.
- The party supplies the stolen key through the documented
x-api-keyheader. - The party invokes API operations available to that key, potentially including instance administration, message transmission, group management, catalog modificat ...[truncated 1092 chars]
- A user follows the documentation and places a valid P-API key and server URL in
- Remediation
View remediation
Remediation Suggestions
-
Replace plaintext credential instructions with an environment-variable or secret-manager workflow:
bash export P_API_BASE_URL="https://your-server.com" export P_API_KEY="$(secret-manager read p-api/key)" curl -X GET "${P_API_BASE_URL}/api/instances" \ -H "x-api-key: ${P_API_KEY}" -
Do not store real credentials in
TOOLS.md, source-controlled files, examples, or agent-readable project documentation. -
If local secret files are unavoidable, keep them outside the repository, enforce restrictive permissions such as
chmod 600, and exclude them through.gitignore. -
Disable or sanitize shell history and command logging when commands may contain secrets.
-
Ensure agents, scripts, and diagnostics redact
x-api-keyheader values from prompts, output, traces, and error reports. -
Apply server-side least privilege by issuing instance-scoped keys with only the required operations.
-
Support key expiration and rotation, and immediately revoke keys suspected of exposure.
-
Add secret scanning to source-control and CI workflows to detect accidentally committed API keys.
-
