T09 · Insecure Skill Coding Practices
- Location
references/cli-examples.md:13- Finding
Explicit Disclosure of Unmasked 1Password Secrets
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This 1Password CLI skill has a legitimate purpose, but some documented workflows can expose passwords, private keys, or other secrets in terminal output or local files.
Review carefully before installing. The skill is for a real and sensitive integration, but users should avoid examples that print secrets, disable masking, capture terminal panes after secret commands, or write decrypted secrets into project directories unless they have explicit permissions, restrictive file modes, cleanup, and credential-rotation plans.
references/cli-examples.md:13Explicit Disclosure of Unmasked 1Password Secrets
SKILL.md:22Mandatory tmux Workflow Can Capture Secret-Bearing Terminal Output
references/cli-examples.md:8Decrypted Secrets May Be Persisted to Unprotected Working-Directory Files
The examples show workflows that resolve secrets and can expose them directly to stdout or persist them to disk, such as writing a private key with --out-file and printing a secret-derived environment variable. In a reference document for a secrets-management CLI, that is dangerous because users may copy these commands into real environments without understanding the disclosure risk.
op run --no-masking -- printenv DB_PASSWORD intentionally resolves a secret into an environment variable and prints it unredacted to stdout. This can disclose the secret to terminal scrollback, shell history tooling, CI logs, or any log collector monitoring command output.
## Run
- `export DB_PASSWORD="op://app-prod/db/password"`
- `op run --no-masking -- printenv DB_PASSWORD`
- `op run --env-file="./.env" -- printenv DB_PASSWORD`
## Inject
op run --env-file="./.env" -- printenv DB_PASSWORD demonstrates loading secrets from an env file and then printing the resolved secret value. Even without --no-masking, this still models a pattern of exposing secrets through stdout and normalizes handling secrets in a way that may leak through logs or debugging output.
- `export DB_PASSWORD="op://app-prod/db/password"`
- `op run --no-masking -- printenv DB_PASSWORD`
- `op run --env-file="./.env" -- printenv DB_PASSWORD`
## Inject
No suspicious patterns detected.