T09 · Insecure Skill Coding Practices
- Location
scripts/generate_image.py:25- Finding
API Key Collected Through Chat, Exposed in Process Arguments, and Persisted in Plaintext
- Content
View full analysis
[api_key]") sys.exit(1) user_prompt = sys.argv[1] # 如果 sys.argv 有第 3 个参数,说明大模型把 Key 传进来了 user_key = sys.argv[2] if len(sys.argv) > 2 else None generate_and_save_image(user_prompt, user_key) ``` The Skill explicitly directs the agent to request and pass the credential through the command line: ```markdown When the user replies with the API Key, rerun using a command containing the Key: python3 scripts/generate_image.py "your expanded image description" "sk-xxxxxxxxxxxx" (The Python script automatically saves it permanently and it does not need to be passed next time.) ``` ### Technical Analysis The Alibaba Cloud API key is handled through three insecure channels: 1. The user is instructed to disclose the key in an agent conversation, where it may remain in conversation history, platform telemetry, diagnostic logs, or backups. 2. The key is passed as a command-line argument. On applicable multi-user systems, command arguments can be exposed through process inspection facilities or captured in shell and agent execution logs. 3. The key is written indefinitely to `scripts/.aliyun_key` as plaintext. The file is opened using the process's default umask rather than being explicitly created with owner-only permissions. The fact that its name begins with a dot ...[truncated 1897 chars]- Remediation
View remediation
