T09 · Insecure Skill Coding Practices
- Location
SKILL.md:42- Finding
Plaintext credentials are written to unsafe temporary files
- Content
View full analysis
/tmp/cred.json < /tmp/cred-$cred_id.json <- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is meant for credential sharing, but its documented workflow stores and handles secrets in ways that can leave plaintext credentials exposed after use.
Review carefully before installing. This skill handles highly sensitive API keys and tokens, but its examples write them to plaintext files in /tmp and persist sent secrets under ~/.pilot/keychain/sent. Use only with credentials that can be quickly revoked or rotated, and prefer a version that uses secure temporary files or in-memory transfer, strict file permissions, verified received paths, and real expiry enforcement.
SKILL.md:42Plaintext credentials are written to unsafe temporary files
SKILL.md:75Plaintext sent credentials persist beyond their declared expiry
SKILL.md:55Untrusted received metadata can direct credential processing to unintended files
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
EOF
pilotctl --json send-file "$RECIPIENT" /tmp/cred.json rm /tmp/cred.json
### Receive Credential
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
for CRED_FILE in ~/.pilot/keychain/received/cred-*.json; do
EXPIRES_AT=$(jq -r '.expires_at' "$CRED_FILE")
[ $(date +%s) -gt $(date -d "$EXPIRES_AT" +%s) ] && rm "$CRED_FILE"
done
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
for CRED_FILE in ~/.pilot/keychain/received/cred-*.json; do
EXPIRES_AT=$(jq -r '.expires_at' "$CRED_FILE")
[ $(date +%s) -gt $(date -d "$EXPIRES_AT" +%s) ] && rm "$CRED_FILE"
done
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
for CRED_FILE in ~/.pilot/keychain/received/cred-*.json; do
EXPIRES_AT=$(jq -r '.expires_at' "$CRED_FILE")
[ $(date +%s) -gt $(date -d "$EXPIRES_AT" +%s) ] && rm "$CRED_FILE"
done
The skill advertises automatic expiration, but the examples only embed an expires_at field and later filter or manually delete files; no automatic enforcement mechanism is shown. Users may assume expired secrets are unusable or removed when they actually remain accessible on disk, causing overtrust in the skill's security properties.
The example writes plaintext credentials to /tmp/cred.json before sending them, exposing secrets to local disclosure risks through predictable paths, weak temp-file handling, race conditions, permissive permissions, swap, backups, or recovery of deleted files. In a credential-sharing skill, plaintext staging materially increases exposure because the content is highly sensitive by design.
The workflow intentionally creates persistent sent/received directories and stores credential material in them, extending the lifetime of secrets beyond their immediate exchange. In the context of a credential-transfer skill, session persistence is more dangerous because compromise of the local account, filesystem, or backups can reveal previously shared secrets long after use.
#!/bin/bash
# Credential lifecycle
mkdir -p ~/.pilot/keychain/{sent,received}
send_credential() {
local recipient="$1"
The workflow example stores sent credential files under ~/.pilot/keychain/sent/, which directly contradicts the stated guidance not to use the skill for persistent credential storage. Because the files contain plaintext secret values, this creates unnecessary local secret retention and expands the window for credential theft by other local users, malware, backups, or forensic recovery.
The 'Cleanup Expired' section documents a loop that removes matching credential files from ~/.pilot/keychain/received, but the markdown provides no warning that files will be permanently deleted. For markdown files, SQP-2 requires warning users about behaviors that could affect data or system integrity, and irreversible deletion qualifies.
No suspicious patterns detected.