T09 · Insecure Skill Coding Practices
- Location
analyzer.js:74- Finding
Detected Secrets Are Persisted Verbatim in a Plaintext Report
- Content
View full analysis
{ secretPatterns.forEach(pattern => { if (pattern.regex.test(line)) { this.addIssue({ file: filePath, line: index + 1, severity: 'critical', category: 'security', title: `Hardcoded ${pattern.name}`, description: 'Sensitive credentials found in code', code: line.trim(), fix: 'Move to environment variables or secure vault', impact: 'Credentials could be exposed in version control or logs' }); } }); }); ``` ```javascript md += `**Code**:\n\`\`\`\n${issue.code}\n\`\`\`\n\n`; md += `**Fix**: \n${issue.fix}\n\n`; md += `**Impact**: \n${issue.impact}\n\n`; md += `---\n\n`; return md; ``` ```javascript if (args.includes('--detailed')) { const report = reviewer.generateReport('markdown'); fs.writeFileSync('code-review-report.md', report); console.log('📄 Detailed report saved to code-review-report.md'); } ``` ### Technical Analysis When a secret-detection pattern matches, the analyzer stores the entire source line in `issue.code`. Markdown report generation then inserts that line without redaction, and detailed mode writes the resulting report to the predictable plaintext path `code-review-report.md`. Consequently, a credential that initially exists in one reviewed source file is copied into a second file. The report may be retained as a CI artifact, committed to version control, uploaded for review, included in backups, or exposed to users who can read generated reports but cannot access the original source. The fixed output name also overwrites any existing file at that path in the current working directory. The principal security concern, however, is disclosur ...[truncated 1350 chars]- Remediation
View remediation
{ const prefix = secret.slice(0, 4); return `${quote}${prefix}…REDACTED${quote}`; }); ``` 2. Prefer reporting only the secret type, file, and line number. Avoid including any portion of passwords and include only a minimal non-sensitive prefix where operationally necessary. 3. Apply redaction before data enters `this.issues`, ensuring JSON, terminal, Markdown, and future output formats are all protected. 4. Create reports with restrictive permissions, such as mode `0o600`, and allow callers to choose an explicit output path: ```javascript fs.writeFileSync(outputPath, report, { mode: 0o600, flag: 'wx' }); ``` 5. Warn before overwriting an existing report or use exclusive creation. 6. Add `code-review-report.md` and report directories to `.gitignore`. 7. Ensure CI systems do not publish unredacted reports or logs as artifacts. 8. Add tests proving that representative API keys, passwords, and tokens never appear in generated terminal, JSON, or Markdown reports. ]]>
