T09 · Insecure Skill Coding Practices
- Location
SKILL.md:61- Finding
Unsafe Storage Guidance for Account Credentials
- Content
View full analysis
Advanced](/?t=settings&s=advanced) 3. Save login credentials as `BMC_EMAIL` + `BMC_PASSWORD` ``` ### Technical Analysis The setup instructions direct users to save a full account email address and password in application settings. They do not require a dedicated secret manager, encryption at rest, access restrictions, log redaction, or credential rotation. The document also does not distinguish protected secret fields from ordinary configuration fields. If the referenced settings system stores values as plaintext or exposes them to other skills, components, logs, backups, support bundles, or users with configuration access, the account password could be disclosed. A reusable account password has substantially broader authority than a narrowly scoped automation token. The affected services are expected to be accessed through browser automation because the document states that Buy Me a Coffee has no public API. This may explain the need for authentication, but it does not make ordinary configuration storage appropriate for a password. ### Attack Path 1. A user follows the setup instructions and stores `BMC_EMAIL` and `BMC_PASSWORD` in the referenced settings interface. 2. The settings backend stores or displays these values without adequate secret protections, or another local component gains permission to read the configuration. 3. The credentials are recovered through configuration access, diagnostic output, logs, backups, an exported settings file, or a compromised component. 4. An attacker authenticates to the associated Buy Me a Coffee or Ko-fi account using the exposed credentials. 5. ...[truncated 901 chars]- Remediation
View remediation
