T09 · Insecure Skill Coding Practices
- Location
SKILL.md:60- Finding
Credential-bearing environment variables are exposed in diagnostic output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 60
Vulnerability Type: Plaintext exposure of environment secrets
Risk Level: MediumVulnerable snippet:
bash env | grep -E "QWENPAW|DASHSCOPE|OPENAI|ANTHROPIC|GITHUB" || trueTechnical Analysis
The environment-inspection workflow instructs the agent to enumerate the complete process environment and print every entry whose name or value matches the listed provider terms. Because
envemits entries asNAME=value, API keys and tokens are printed in plaintext rather than merely reporting whether required variables are configured.This behavior is broader than the Skill's diagnostic need. The report format only requires an availability result, while the command can expose credentials belonging to QwenPaw and unrelated services such as GitHub, OpenAI, Anthropic, and DashScope. It also conflicts with the stated scope that the Skill does not handle API keys.
The trust boundary is crossed when secrets available only to the local process are copied into command output visible to the agent. That output may subsequently be retained in tool transcripts, agent context, diagnostic reports, or associated logs. The project contains no evidence of deliberate exfiltration or malicious intent, so this is classified as a reachable coding flaw rather than credential theft.
Attack Path
- A user, shell profile, CI environment, or credential tool defines a matching variable containing an API key or access token.
- The user invokes the environment-inspector Skill for routine diagnostics.
- The prescribed check executes
envand filters its plaintext output. - The matching variable's complete
NAME=valueentry is emitted. - The credential enters agent-visible command output and may be retained in transcripts, reports, or logs accessible beyond the process that originally held it.
Impact Assessment
Successful exposure reveals the full values o ...[truncated 515 chars]
- Remediation
View remediation
Remediation Suggestions
Replace environment enumeration with an explicit allowlist of variables genuinely required by QwenPaw, and report only whether each variable is set. Never print secret values.
For example:
bash for key in QWENPAW_REQUIRED_VAR; do if [ -n "$(printenv "$key")" ]; then printf '%s=set\n' "$key" else printf '%s=unset\n' "$key" fi doneAdditionally:
- Remove unrelated provider variables from the diagnostic scope unless they are demonstrably required.
- Ensure generated reports contain only boolean presence indicators or redacted values.
- Document that raw environment-variable values must not be included in agent responses, transcripts, or logs.
- If partial identification is necessary, use strict redaction that never reveals enough of a token to authenticate.
