other
- Location
SKILL.md:23- Finding
Plaintext Secrets Transmitted to an External Third-Party Service
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 23–26
Vulnerability Type: External transmission and potential exfiltration of sensitive credentials
Risk Level: Highbash curl -s -X POST https://cloak.opsy.sh/api/secrets \ -H "Content-Type: application/json" \ -d '{"secret":"YOUR_SECRET_HERE"}'Technical Analysis
The Skill instructs the agent to place API keys, passwords, tokens, or other secrets directly into a JSON request body and transmit that body to the external service
https://cloak.opsy.sh.Although the Skill describes the resulting links as encrypted, the audited project contains only
SKILL.md. It provides no client-side encryption implementation, cryptographic design, service implementation, or other evidence demonstrating that the secret is encrypted before reaching the remote server. Based on the documented command, the remote API receives the secret value as plaintext application data inside the HTTPS request.TLS protects data in transit from passive network observers but does not prevent the destination service, its operators, application logs, monitoring systems, or an attacker who compromises the service from accessing the submitted value.
Attack Path
- A user invokes the Skill to share a password, API key, token, or similar credential.
- The agent substitutes the sensitive value into the
secretproperty of the JSON request body. curlsends the value tocloak.opsy.sh.- The external service processes or stores the secret and returns a retrieval identifier and key.
- A malicious service operator, compromised server, exposed application log, or attacker with access to the service infrastructure obtains the submitted secret.
- The acquired credential is used against the system or account for which it is valid.
Impact Assessment
The exposed privileges depend on the submitted secret. Potential consequences include:
- Unauthorized access to user, service, database, cloud, or admin ...[truncated 533 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not send plaintext secrets to an unverified or unapproved third-party service.
- Implement authenticated client-side encryption before transmission so the server receives ciphertext only.
- Generate and retain the encryption key exclusively on the client. If a URL fragment is used, ensure the fragment is never transmitted to the server.
- Use a reviewed authenticated-encryption construction, such as AES-GCM or XChaCha20-Poly1305, through a mature cryptographic library.
- Publish and independently review the client implementation and cryptographic protocol rather than relying on an undocumented encryption claim.
- Use an organization-approved or self-hosted endpoint with appropriate access controls, audit logging, retention limits, and incident-response procedures.
- Prevent plaintext secrets from appearing in shell history, process arguments, debug output, application logs, telemetry, or temporary files.
- Obtain explicit user confirmation before transferring any credential to an external service and clearly identify the destination and trust boundary.
- Apply short expiration periods and one-time retrieval only as defense-in-depth; these controls do not replace client-side encryption.
