T09 · Insecure Skill Coding Practices
- Location
SKILL.md:65- Finding
API Keys Stored in Predictable Plaintext Files Without Enforced Access Controls
- Content
View full analysis
~/.config/kdca/api_key mkdir -p ~/.config/data-go-kr && echo "YOUR_KEY" > ~/.config/data-go-kr/api_key ``` Related references to the same credential-storage design appear in `playbook.md`, lines 126–132, and `scripts/README.md`, lines 11–13. ### Technical Analysis The documented setup commands place API credentials in predictable plaintext files without explicitly restricting the permissions of either the parent directories or the files. The effective permissions therefore depend on the user's current `umask`. In an environment with permissive defaults, other local users or compromised processes may be able to read the credentials. The instructions also encourage users to substitute a real credential directly into an interactive shell command. Such a command may be retained in shell history, terminal logs, session recording systems, or administrative auditing records. Restricting the resulting file permissions would not remove those secondary copies. No hardcoded real credentials were found in the project. The vulnerability concerns the documented method by which users are instructed to provision future credentials. ### Attack Path 1. A user replaces `YOUR_KEY` with a valid KDCA or data.go.kr API key and executes the documented command. 2. The shell may record the command, including the credential, in its history. 3. The resulting directory and credential file inherit permissions determined by the user's existing `umask`, because the instructions do not enforce restrictive modes. 4. Another local account, a compromised process running on the same host, or an operator with access to terminal-history records obtains the key. 5. The attacker submits unauthorized requests to the correspondi ...[truncated 883 chars]- Remediation
View remediation
