T09 · Insecure Skill Coding Practices
- Location
sample_state.json:2664- Finding
Bundled State File Discloses Private Repository and Personnel Activity Data
- Content
View full analysis
Vulnerability Details
File Location:
sample_state.json:2664-2717
Additional Evidence:sample_state.json:19-29
Vulnerability Type: Sensitive information exposure through a distributed state artifact
Risk Level: HighVulnerable Data Snippet
json "author": { "login": "tenkus47", "id": 42644738, "node_id": "MDQ6VXNlcjQyNjQ0NzM4", "avatar_url": "https://avatars.githubusercontent.com/u/42644738?v=4", "url": "https://api.github.com/users/tenkus47", "html_url": "https://github.com/tenkus47" }, "parents": [ { "url": "https://api.github.com/repos/OpenPecha/url-shortening/commits/b28ad7092f14d57b54ecf5f7aae4b2b6494a8528", "html_url": "https://github.com/OpenPecha/url-shortening/commit/b28ad7092f14d57b54ecf5f7aae4b2b6494a8528", "sha": "b28ad7092f14d57b54ecf5f7aae4b2b6494a8528" } ], "repository": { "id": 969515297, "node_id": "R_kgDOOcmhIQ", "name": "url-shortening", "full_name": "OpenPecha/url-shortening", "private": true, "owner": { "login": "OpenPecha", "id": 82142807 }, "html_url": "https://github.com/OpenPecha/url-shortening", "description": "Implementation of url shorterning" }Other records in the same file include personal email addresses, commit messages, commit hashes, timestamps, API URLs, and account metadata.
Technical Analysis
The package includes a 545 KB state snapshot containing raw GitHub API responses. At least one record explicitly identifies a private repository and associates it with a named contributor and commit history.
Runtime or example data distributed with a Skill should be synthetic and minimized. A monitor only needs aggregated activity data, such as a username and the number of active days. Raw API responses containing repository visibility, commit identifiers, email addresses, messages, and extensive account metada ...[truncated 1595 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
sample_state.jsonfrom the distributed package immediately. - Purge the artifact from source-control history, release archives, package registries, build caches, and mirrors where feasible.
- Determine who received the artifact and perform incident review under the organization’s data-exposure process.
- Replace the file with a small, fully synthetic example containing fictitious usernames, repositories, hashes, dates, and email addresses.
- Add
state.json,sample_state.json,monitor.log, and similar runtime artifacts to.gitignoreand packaging exclusion rules. - Add automated secret and sensitive-data scanning that rejects examples containing private repository flags, real email addresses, raw API responses, or organization-specific identifiers.
- Store only the minimum aggregates necessary for monitoring rather than complete API response objects.
- Remove
