T09 · Insecure Skill Coding Practices
- Location
SKILL.md:23- Finding
Hard-Coded Git Access Token and Plaintext Repository Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 23–25
Vulnerability Type: Hard-coded credential and plaintext transmission configuration
Risk Level: HighVulnerable Code
markdown ## Repository - **URL**: http://git.homelab:3000/vitali/SigmaFlow-Svelte.git - **Token**: c865b793f09a3b79b65ebdfbd75c5b17395188d2Technical Analysis
The Skill documentation embeds a credential-like Git access token in plaintext. Anyone who can read the distributed Skill package, repository contents, cached copies, logs, or revision history can recover the token and attempt to authenticate to the specified Git service.
The repository URL also uses unencrypted HTTP. If this endpoint or token is used over a network without an independent encrypted transport layer, repository traffic and credentials may be exposed to passive interception or active man-in-the-middle attacks.
The reviewed
scripts/deploy.shfile does not directly read this token or configure the documented URL; it runsgit pushusing the current repository's existing Git configuration. Nevertheless, publishing the token is independently unsafe because it makes the secret available to every reader ofSKILL.md.Attack Path
- An attacker obtains access to the Skill package, source repository, artifact cache, backup, or commit history.
- The attacker reads
SKILL.mdand extracts the hard-coded token and Git repository endpoint. - The attacker attempts to authenticate to the Git service using the exposed token.
- If the token remains valid, the attacker performs any repository operations allowed by its assigned scopes.
- If write access is available, the attacker may modify source code or deployment content, potentially creating a downstream supply-chain compromise.
A network-positioned attacker could additionally monitor or manipulate traffic if the Git service is accessed through the documented plaintext HTTP endpoint.
I
...[truncated 547 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke the exposed token immediately and issue a replacement only if it is still required.
- Review Git service audit logs for use of the token from unexpected users, addresses, or systems.
- Remove the token from
SKILL.md, all repository revisions, release artifacts, caches, backups, and generated documentation where feasible. - Store replacement credentials in a dedicated secret manager, operating-system credential store, or protected environment variable. Never include them in source or documentation.
- Grant the replacement token only the minimum repository permissions required, and apply expiration and rotation policies.
- Replace the HTTP repository endpoint with HTTPS and enforce certificate validation. Disable plaintext HTTP access where possible.
- Add automated secret scanning and pre-commit or CI checks to prevent credentials from being committed again.
- Keep
scripts/deploy.shdependent on securely configured Git credentials rather than embedding credentials in command arguments, files, or remote URLs.
