T09 · Insecure Skill Coding Practices
- Location
scripts/generate_fixtures.py:15- Finding
Real OpenAI API Key Written to Plaintext Test Fixtures
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate_fixtures.py, lines 15–22
Vulnerability Type: Plaintext credential exposure
Risk Level: HighVulnerable Code
python def agent_config_fixture(name: str, model: str = "gpt-4o") -> dict: return { "name": name, "type": "TextAgent", "model_config": { "model": model, "api_key": os.environ.get("OPENAI_API_KEY", "test-api-key"), }, "sys_prompt": f"You are {name}, a helpful assistant for testing.", }Generated configurations are subsequently serialized to plaintext fixture files, including:
python write( output_dir / "sequential" / "pipeline.json", json.dumps(pipeline, indent=2, ensure_ascii=False), )Technical Analysis
agent_config_fixture()reads the realOPENAI_API_KEYfrom the process environment whenever it is available. The resulting value is inserted directly into each generated agent'smodel_config.The sequential, parallel, and team fixture generators place these configurations into pipeline dictionaries and serialize them as plaintext JSON under the user-selected output directory. The
allpattern invokes all affected generators.This behavior crosses a trust boundary by moving a secret from protected process environment state into ordinary test-fixture files. It also contradicts the security statement in
SKILL.mdthat generated fixtures do not embed real credentials. Test fixtures are commonly committed to source control, retained as CI artifacts, or shared with other developers, making them an inappropriate destination for live credentials.No evidence indicates that the key is transmitted to an attacker-controlled endpoint or that the author intended credential theft. The issue is therefore an insecure, reachable implementation flaw rather than confirmed malicious behavior.
Attack Path
- A developer or CI ...[truncated 1067 chars]
- Remediation
View remediation
Remediation Suggestions
- Never copy
OPENAI_API_KEYor another live credential into generated fixtures. - Always emit an inert placeholder such as
test-api-key, or emit a non-secret environment-variable reference that the consuming test resolves at runtime. - If optional live-provider validation is required, read the credential only in memory during the validation operation and never include it in serialized configuration, logs, exceptions, or generated files.
- Add a regression test that sets
OPENAI_API_KEYto a sentinel secret, generates every supported pattern, and verifies that the sentinel does not appear anywhere in the output tree. - Update
SKILL.mdso its credential-handling documentation accurately reflects the implementation and clearly separates mock fixture generation from any optional live-provider validation workflow.
- Never copy
