T09 · Insecure Skill Coding Practices
- Location
SKILL.md:61- Finding
Plaintext Persistence of the Seko API Key
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 61–64
Vulnerability Type: Plaintext sensitive-data storage
Risk Level: MediumVulnerable Instruction
text ### Step 2 Set the SEKO_API_KEY environment variable. Check whether the current environment variables include SEKO_API_KEY. If it is not set, explicitly ask the user to provide SEKO_API_KEY and tell the user that it can be obtained from https://seko.sensetime.com/explore. If SEKO_API_KEY is obtained, save it to .env. Then set the environment variable from .env and verify that it is correctly configured.The snippet above is an English translation of the original instruction at the cited location.
Technical Analysis
The Skill explicitly directs the Agent to persist the user's Seko API credential in a
.envfile. It does not specify:- A protected storage location outside the project workspace
- Owner-only file permissions
- User consent for persistent credential storage
- Exclusion from version control
- Secret-manager integration
- Credential expiration, rotation, or cleanup
Although using the API key to authenticate to the declared Seko service is necessary for the Skill's functionality, persistent plaintext storage is not required. The scripts already support reading
SEKO_API_KEYdirectly from the process environment, so the.envpersistence instruction exceeds the minimum storage privilege needed for authenticated API calls.Attack Path
- The user supplies a valid
SEKO_API_KEY. - Following
SKILL.md, the Agent writes the credential into{PROJECT_DIR}/.env. - The project directory is committed to version control, archived, backed up, shared with another party, or read by another local process or user.
- The unauthorized party retrieves the plaintext credential.
- The exposed key is reused against the Seko API until it is revoked or expires.
This path does not require code execution within ...[truncated 652 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to save
SEKO_API_KEYto{PROJECT_DIR}/.env. - Read the credential from the existing process environment, which all authenticated scripts already support.
- When persistence is necessary, require explicit informed user consent and use an operating-system credential store or managed secret service.
- If a
.envfile must be supported:- Store it outside shared project content.
- Create it with owner-only permissions, such as mode
0600on POSIX systems. - Add
.envto.gitignorebefore creating the file. - Never print or include its value in logs, command examples, task records, or error messages.
- Delete it when the workflow finishes unless the user explicitly requests retention.
- Prefer short-lived, least-privileged API credentials and document revocation and rotation procedures.
- Continue sending the key only to the fixed HTTPS Seko API host; validate the configured hostname against an allowlist before attaching the authentication header.
- Remove the instruction to save
