T09 · Insecure Skill Coding Practices
- Location
SKILL.md:59- Finding
Decrypted Bitwarden Secrets Exposed Through Standard Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:59-74;references/cli-examples.md:13-59;references/cli-examples.md:115-127
Vulnerability Type: Decrypted secret disclosure through agent-visible command output
Risk Level: HighVulnerable Code
SKILL.md:59-74bash # Get password by item name bw get password "GitHub" # Get username bw get username "GitHub" # Get TOTP code bw get totp "GitHub" # Get full item as JSON bw get item "GitHub" # Get specific field bw get item "GitHub" | jq -r '.fields[] | select(.name=="api_key") | .value' # List all items bw list itemsreferences/cli-examples.md:13-59bash # Simple lookup (requires unique name) bw get password "GitHub" # If multiple items match, use item ID bw get password 12345678-1234-1234-1234-123456789012 # Get username bw get username "GitHub" # Returns current 6-digit code bw get totp "GitHub" # Get full item (JSON) bw get item "GitHub" # Pretty print bw get item "GitHub" | jq . # Extract specific login fields bw get item "GitHub" | jq -r '.login.username' bw get item "GitHub" | jq -r '.login.password' bw get item "GitHub" | jq -r '.login.totp' # List all custom fields bw get item "AWS Credentials" | jq '.fields' # Get specific custom field by name bw get item "AWS Credentials" | jq -r '.fields[] | select(.name=="access_key") | .value' # Get hidden field bw get item "AWS Credentials" | jq -r '.fields[] | select(.name=="secret_key") | .value' # Get note content bw get notes "My Secure Note" # Full item with metadata bw get item "My Secure Note" | jq -r '.notes'references/cli-examples.md:115-127bash # Single credential export GITHUB_TOKEN=$(bw get password "GitHub Token") # Multiple credentials export AWS_ACCESS_KEY_ID=$(bw get item "AWS" | jq -r '.fields[] | select(.name=="access_key") | .value') export AWS_SECRET_ACCESS_KEY=$(bw get ite ...[truncated 3002 chars]- Remediation
View remediation
Remediation Suggestions
- Remove examples that directly print passwords, TOTP values, secure notes, hidden fields, or complete vault items to stdout.
- Explicitly prohibit agents from returning retrieved secret values in tool output, chat responses, logs, or diagnostic messages.
- Provide a hardened wrapper that retrieves only the required field and passes it directly to a narrowly scoped child process without returning secret-bearing stdout.
- Disable shell tracing with
set +xbefore any secret operation and ensure command runners do not echo expanded commands or environment values. - Avoid complete-item retrieval when only one field is needed. Apply least-data-access principles to every vault operation.
- Require explicit user confirmation before accessing sensitive vault fields, especially passwords, TOTP material, secure notes, and administrative credentials.
- Configure execution frameworks to redact known secret-bearing outputs and prevent tool results from being persisted in telemetry or conversation history.
- Unset temporary secret variables immediately after use, restrict child-process inheritance, and run
bw lockas soon as the operation is complete. - Document residual risks of environment-variable injection, including exposure through process inspection, crash reports, debugging tools, and inherited environments.
- Add automated documentation checks that reject examples containing direct secret-output patterns such as
bw get password,bw get totp, unfilteredbw get item, andjq -rextraction of secret fields unless output is safely contained.
