T09 · Insecure Skill Coding Practices
- Location
SKILL.md:29- Finding
Plaintext Binance API Key Storage in Skill Configuration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:29-38
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: MediumThe Skill instructs users to place their Binance Square OpenAPI key directly inside
SKILL.md:yaml config: accounts: - name: default api_key: 你的API密钥Technical Analysis
Storing a live API key in a Markdown Skill definition violates secure secret-management practices. Skill directories may be committed to version control, copied between systems, included in backups, submitted for support, indexed by development tools, or exposed to other local processes and agents.
Although the document separately advises users not to disclose the complete key publicly, that warning does not mitigate the risk introduced by directing users to persist the credential in a shareable project document.
An exposed key could be supplied through the documented
X-Square-OpenAPI-KeyHTTP header to authenticate requests to the Binance Square publishing endpoint.Attack Path
- A user follows the configuration instructions and writes a valid Binance Square OpenAPI key into
SKILL.md. - The Skill directory is committed, shared, archived, backed up, or accessed by another user or local component.
- An attacker reads and extracts the plaintext API key.
- The attacker sends requests to the documented Binance Square content publishing endpoint using the stolen key.
- Unauthorized content is published under the affected user's Binance Square identity until the key is revoked, expires, or reaches its posting limit.
Impact Assessment
Exploitation does not grant general operating-system or Binance account privileges based on the reviewed files. The scope is limited to the permissions associated with the exposed Square OpenAPI key. Those permissions may allow unauthorized publication of posts, reputational damage, spam or policy violations, consumption of posting qu ...[truncated 76 chars]
- A user follows the configuration instructions and writes a valid Binance Square OpenAPI key into
- Remediation
View remediation
Remediation Suggestions
- Do not store API keys in
SKILL.md,README.md, or any other version-controlled project document. - Retrieve the credential at runtime from a protected secret manager or an environment variable such as
BINANCE_SQUARE_API_KEY. - If local configuration is required, use a file excluded from version control and restrict its permissions to the owning user.
- Provide only placeholder values in an example file such as
.env.example. - Add relevant secret-bearing files to
.gitignore. - Implement automated secret scanning in source-control and release workflows.
- Document immediate key revocation and rotation procedures for suspected exposure.
- Configure the API key with the minimum permissions supported by Binance and monitor it for unauthorized publishing activity.
- Do not store API keys in
