T09 · Insecure Skill Coding Practices
- Location
src/config.ts:31- Finding
API keys are stored in a configuration file without restrictive permissions
- Content
View full analysis
; } ``` ### Technical Analysis `saveConfig()` writes `~/.config/tokenrip/config.json` without specifying a restrictive file mode. On a typical Unix system with a `022` umask, a newly created file receives mode `0644`, allowing other local users to read it. The file contains the bearer API key set during registration, key recovery, key rotation, or `rip config set-key`. This differs from `saveIdentity()`, which correctly creates the private-key file with mode `0600`. The absence of an explicit mode also means that updating an existing configuration file does not repair previously insecure permissions. ### Attack Path 1. A user runs `rip auth register`, `rip auth create-key`, or `rip config set-key`. 2. The returned API key is placed in the configuration object. 3. `saveConfig()` creates `~/.config/tokenrip/config.json` using permissions derived only from the process umask. 4. On a multi-user system, another local account reads the file. 5. The attacker extracts the bearer API key. 6. The attacker sends authenticated requests to the Tokenrip API as the victim agent. ### Impact Assessment A local attacker may obtain all Tokenrip privileges granted to the API key. Depending on server-side authorization, this can include reading private inbox messages and threads, accessing or ...[truncated 276 chars]- Remediation
View remediation
