T09 · Insecure Skill Coding Practices
- Location
skill.md:27- Finding
Vercel Access Token Requested Through Conversation Content
- Content
View full analysis
"Open vercel.com/account/tokens → Create Token → copy it and send it here. You only need to do this once." 2. Once received, verify: ```bash export VERCEL_TOKEN= vercel whoami ``` 3. Store securely — do NOT write the token to `~/.zshrc` or any file. Keep it in env for this session only, or ask the user to add it to their secrets manager. ``` ### Technical Analysis The skill explicitly instructs the user to send a Vercel access token through the conversation. Access tokens are bearer credentials: possession is generally sufficient to exercise the permissions granted to the token. Although the skill subsequently recommends keeping the token in an environment variable, that does not address the initial disclosure. Before being exported, the token has already entered the conversation and may consequently be retained in chat history, agent traces, application logs, monitoring systems, or other infrastructure that processes prompts. This design contradicts the principle that secrets should only be entered through dedicated secret-input channels. The absence of hardcoding does not make the workflow secure because the credential is still transmitted as plaintext conversation content. ### Attack Path 1. A headless agent activates the skill for a Vercel-related task. 2. The skill asks the user to create a Vercel token and send it through the conversation. 3. The user submits the bearer token as ordinary message content. 4. The token becomes available to systems or personnel with access to conversation records, logs, traces, or prompt-processing infrastructure. 5. An unauthorized party retrieves the token and uses it with the Vercel CLI or API. 6. The party performs any proj ...[truncated 635 chars]- Remediation
View remediation
