T09 · Insecure Skill Coding Practices
- Location
SKILL.md:7- Finding
Hard-Coded Composio API Credential and Personal Account Metadata
- Content
View full analysis
- Remediation
View remediation
" ``` 4. Store credentials in a dedicated secret manager or another access-controlled credential store rather than documentation or shell startup files. 5. If environment variables remain necessary, inject them only into the specific process that needs them rather than globally exporting them from `~/.bashrc`. 6. Create a narrowly scoped credential limited to the required Gmail and Google Tasks operations. 7. Review Composio audit logs for use of the exposed key and investigate unexpected tool executions. 8. Add automated secret scanning and pre-commit checks to prevent future credential commits. ]]>
