T09 · Insecure Skill Coding Practices
- Location
scripts/query_fee.py:34- Finding
API credentials are persisted in a plaintext file with no restrictive permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/query_fee.py, lines 34-37
Vulnerability Type: Plaintext credential storage
Risk Level: HighVulnerable Code
python def save_auth(base_url: str, agent_no: str, api_key: str): """保存认证信息""" with open(AUTH_FILE, "w", encoding="utf-8") as f: json.dump({"baseUrl": base_url, "agentNo": agent_no, "apiKey": api_key}, f)The function is invoked after every query, regardless of whether the request or authentication succeeded:
python # 保存认证信息(不管成功失败都保存) save_auth(base_url, agent_no, api_key)Technical Analysis
The reusable AES API key, agent identifier, and API destination are written directly to
scripts/.auth.jsonwithout encryption or an explicit restrictive file mode. The permissions therefore depend on the process umask and runtime environment. Other local users, processes, backup systems, repository scanners, or diagnostic tools may be able to read the resulting file.Persisting credentials is part of the declared convenience functionality, but plaintext storage is not the minimum privilege necessary. Saving the values after failed requests also allows invalid or attacker-influenced credentials and destinations to replace previously valid state.
Attack Path
- A user executes a merchant-fee query with an API key.
- The script calls
save_autheven if the network request or authentication fails. - The key, agent number, and destination are written in plaintext to
scripts/.auth.json. - A local process or user with read access retrieves the file.
- The exposed key is reused to decrypt compatible traffic, forge encrypted requests, or access the API within the key's authorization scope.
Impact Assessment
Successful exploitation exposes a reusable API credential and its associated agent identity. The attacker obtains the same API authorization scope granted to that key; the exact merchant and API o ...[truncated 183 chars]
- Remediation
View remediation
Remediation Suggestions
- Store the API key in an operating-system credential manager or dedicated secrets service.
- If file storage is unavoidable, create the file atomically with mode
0600, verify its owner and permissions before reading, and place it outside the distributed Skill directory. - Do not store the API key unless the user explicitly opts in.
- Save or replace authentication state only after a successfully authenticated response.
- Separate endpoint configuration from credentials and validate both before persistence.
- Implement credential rotation and secure deletion procedures.
