T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:131- Finding
Overbroad and Inconsistent Access to Credential-Bearing Files
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 131–144
Vulnerability Type: Excessive access to credential-bearing files
Risk Level: MediumVulnerable Instructions
The following is an English translation of the complete relevant instructions:
text - Credential read: `$HOME/.config/platform/config.json`text 1. Confirm that the configuration file `$HOME/.json` exists and that the API key is valid.Technical Analysis
The Skill instructs the Agent to access files in the user's home directory that may contain API credentials. It does not define the exact configuration fields that may be read, prohibit returning file contents, require secret redaction, or provide an implementation demonstrating that unrestricted credential-file access is necessary.
The two instructions also identify inconsistent paths:
$HOME/.config/platform/config.jsonand the unusually broad$HOME/.json. This inconsistency can cause an Agent to inspect an unintended file containing unrelated credentials or private configuration.Although the filtering workflow may legitimately require an API token, credential handling should be restricted to a dedicated environment variable or a narrowly scoped configuration field. The current instructions unnecessarily expose secret-bearing files to the Agent and its tool context.
No evidence was found that the Skill deliberately transmits credentials to an external service. The risk is unauthorized exposure through Agent context, command output, execution logs, or downstream generated content rather than confirmed exfiltration.
Attack Path
- A user activates the Skill to scan or filter a community feed.
- The Agent follows the setup instructions and accesses one of the specified home-directory configuration files.
- Because the allowed fields and access method are not constrained, the Agent may read the complete file while attempting to validate the API key.
...[truncated 789 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove instructions that encourage reading complete credential-bearing files.
- Use a dedicated environment variable such as
PLATFORM_API_KEYand access only that variable. - If a configuration file is required, standardize on one application-specific path and document the exact permitted JSON field.
- Explicitly prohibit printing, logging, returning, or persisting API keys and complete configuration-file contents.
- Validate only whether the required field is present; do not display its value.
- Redact tokens in errors and diagnostic output, retaining only a short non-sensitive identifier if necessary.
- Require a narrowly scoped, read-only API token with minimal permissions and support straightforward token rotation.
- Remove the conflicting
$HOME/.jsonreference and use a clearly named application-specific file with restrictive filesystem permissions. - Add an executable implementation that performs bounded parsing and secret-safe validation so credential handling can be independently audited.
