T09 · Insecure Skill Coding Practices
- Location
scripts/hot_scanner.py:22- Finding
Excessive Credential Exposure to the Third-Party bird CLI
- Content
View full analysis
- Remediation
View remediation
dict[str, str]: allowed = {"AUTH_TOKEN", "CT0"} credentials = {} if path.exists(): for raw_line in path.read_text(encoding="utf-8").splitlines(): line = raw_line.strip() if not line or line.startswith("#") or "=" not in line: continue key, value = line.split("=", 1) key = key.strip() if key in allowed: credentials[key] = value.strip().strip('"').strip("'") return credentials ``` 2. Do not write `.env` values into the global `os.environ`. 3. Construct a minimal environment for `bird`. Include only required credentials and narrowly selected runtime variables: ```python credentials = load_bird_credentials(ENV_FILE) bird_env = { "PATH": os.environ.get("PATH", ""), "HOME": os.environ.get("HOME", ""), "LANG": os.environ.get("LANG", "C.UTF-8"), **credentials, } result = subprocess.run( [bird_bin, "search", query, "-n", "15", "--json"], capture_output=True, text=True, timeout=30, env=bird_env, check=False, ) ``` 4. Validate that both credentials are present before enabling Twitter scanning, and otherwise skip the integration with a clear warning. 5. Use a project-local, version-pinned `bird` executable and verify its expected path and integrity before execution. 6. Restrict `.env` file permissions to the owning user and document that it must contain only Twitter-specific credentials. 7. Prefer a scoped API credential over browser session cookies when the upstream service supports one. Browser session tokens can provide broader account access than the scanner requires. 8. Avoid logging credential values, child environments, or raw subprocess diagnostic output that might contain secrets. ]]>
