T09 · Insecure Skill Coding Practices
- Location
SKILL.md:39- Finding
Plaintext Storage of Email API Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 39-49
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: MediumThe documented configuration instructs users to store an email API key directly in
~/.email-monitor/config.json:json { "inboxes": [ { "name": "work", "provider": "agentmail", "api_key": "your_key", "inbox_id": "you@agentmail.to" } ],Technical Analysis
API credentials are sensitive authentication material. The documented configuration embeds the API key directly in a plaintext JSON file without requiring restrictive file permissions, validating file ownership, referencing an operating-system credential store, or offering an environment-based secret mechanism.
Although the example contains only the placeholder value
your_key, users following these instructions would replace it with a real credential. The resulting file may then be readable by other local accounts or processes if it is created with permissive permissions. The credential may also leak through backups, support bundles, home-directory synchronization, or accidental source-control inclusion.The artifact contains only documentation, so the implementation's actual permission handling and credential-loading behavior could not be verified.
Attack Path
- A user follows the documented setup instructions and places a valid AgentMail API key or equivalent mailbox credential in
~/.email-monitor/config.json. - The configuration file is created with permissions that allow an unauthorized local user or process to read it, or the file is copied into an exposed backup or repository.
- The attacker extracts the plaintext credential from the JSON file.
- The attacker uses the credential against the associated email provider's API.
- The attacker gains whatever mailbox operations and data access are authorized by that credential.
Impact Ass
...[truncated 563 chars]
- A user follows the documented setup instructions and places a valid AgentMail API key or equivalent mailbox credential in
- Remediation
View remediation
Remediation Suggestions
- Store API keys in an operating-system credential manager or dedicated secret-management service rather than directly in the JSON configuration.
- If file-based configuration is required, allow the JSON file to reference an environment variable or secret identifier instead of containing the secret value.
- Create the configuration file with permission mode
0600and verify that it is owned by the current user before reading credentials from it. - Refuse to load credentials from files that are group-readable, world-readable, or owned by another user.
- Add explicit documentation warning users not to commit the configuration file to source control, include it in support bundles, or place it in insecure synchronized storage.
- Recommend narrowly scoped, revocable credentials and document a credential-rotation procedure for suspected exposure.
- Provide a
.gitignoreexample covering.email-monitor/config.jsonwhen project-local configuration is supported.
