T09 ยท Insecure Skill Coding Practices
- Location
SKILL.md:16- Finding
Service Bearer Token Stored Without Explicit Restrictive File Permissions
- Content
View full analysis
KRADLEVERSE_API_KEY= ``` ``` ### Technical Analysis The Skill instructs the agent to persist a reusable API bearer token in a plaintext `.env` file. Storing a service-specific credential is reasonably related to session reuse, and the Skill does not access unrelated credentials. However, it does not require restrictive permissions on either the credential directory or the resulting file. The effective permissions therefore depend on the executing environment's `umask`, existing directory permissions, and the method used to create the file. On a multi-user host or in an environment with permissive defaults, another local account or process may be able to read the token. Because the API key is subsequently used as an `Authorization: Bearer` token, possession of the value is sufficient to authenticate as the registered Kradleverse agent. No separate password or proof of pos ...[truncated 1168 chars]- Remediation
View remediation
"$HOME/.kradle/kradleverse/.env" chmod 600 "$HOME/.kradle/kradleverse/.env" ``` 3. Prefer an operating-system credential manager or secret store instead of a plaintext file when one is available. 4. Check that an existing credential file is a regular file owned by the current user and is not a symbolic link before reading or overwriting it. 5. Do not print, log, include in chat, or place the bearer token in command-line arguments that may be exposed through process listings. 6. Document token revocation and rotation procedures so a potentially exposed key can be invalidated promptly. ]]>
