T09 · Insecure Skill Coding Practices
- Location
SAFETY.md:136- Finding
Credential Verification Commands Disclose Alpaca API Secrets
- Content
View full analysis
Vulnerability Details
File Location:
SAFETY.md:136-137
Vulnerability Type: Plaintext credential disclosure
Risk Level: HighVulnerable code:
bash echo "Key ID set: ${APCA_API_KEY_ID:-(not set)}" echo "Secret key set: ${APCA_API_SECRET_KEY:-(not set)}"Technical Analysis
The documented commands are presented as a way to verify that credentials are configured without displaying their values. However, the shell parameter expansion
${VARIABLE:-(not set)}returns the complete value ofVARIABLEwhenever it is set and nonempty. Consequently, both commands print the actual Alpaca key ID and secret key to standard output.This behavior directly conflicts with the credential-exposure guardrail in
SKILL.md, which prohibits displaying, echoing, logging, or encoding actual API credential values. Terminal output may also be retained in shell transcripts, agent conversation history, CI logs, screen recordings, or centralized logging systems.Attack Path
- An attacker or misleading instruction asks the user or agent to verify whether Alpaca credentials are configured.
- The user or agent follows the supposedly safe commands in
SAFETY.md. - The shell expands both environment variables to their actual values.
- The credentials are printed to the terminal and may be captured by conversation history, logs, monitoring software, or another person with access to the session.
- An attacker who obtains the credentials authenticates to the Alpaca API and performs operations allowed by those credentials.
Impact Assessment
Successful exploitation discloses both required Alpaca API authentication values. An attacker could obtain the trading API privileges associated with the affected account, potentially including access to sensitive account and portfolio information, order submission, order cancellation, and position management. If live-trading credentials are exposed, unauthorized operations ...[truncated 197 chars]
- Remediation
View remediation
Remediation Suggestions
Replace value-expanding commands with presence tests that never print credential contents:
bash if [ -n "${APCA_API_KEY_ID:-}" ]; then echo "Key ID is set" else echo "Key ID is not set" fi if [ -n "${APCA_API_SECRET_KEY:-}" ]; then echo "Secret key is set" else echo "Secret key is not set" fiAdditional hardening measures:
- Remove all examples that use
echo,printf,env,set, or similar commands to display credential variables. - Recommend a read-only API operation, such as
apcacli account get, when credential validity must be tested. - Ensure logs and command transcripts redact
APCA_API_KEY_IDandAPCA_API_SECRET_KEY. - Add an automated documentation test that rejects direct expansion of sensitive environment variables in output commands.
- If the vulnerable commands have already been used in a logged environment, rotate both credentials and revoke the previous keys.
- Remove all examples that use
