T09 · Insecure Skill Coding Practices
- Location
SKILL.md:37- Finding
Full 1Password Credential Records May Be Exposed Through Captured Command Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 37
Vulnerability Type: Sensitive credential exposure through command output
Risk Level: HighVulnerable Code Snippet:
bash source ~/.zshrc 2>/dev/null && op item get "<ITEM_NAME>" --vault "<VAULT_NAME>" --format json 2>&1Technical Analysis
The documented command retrieves the complete 1Password item as JSON. The returned object can contain username and password fields, URLs, and other sensitive item metadata. Because standard error is redirected to standard output with
2>&1, all command output is sent through the same output channel.Although the subsequent instructions prohibit printing or logging the password, that policy does not prevent the command-execution framework, agent transcript, telemetry system, debugging layer, or tool-call history from capturing the raw JSON before it is parsed. The implementation therefore exposes substantially more sensitive information than is required for browser authentication.
Attack Path
- A user or attacker requests that the agent log in using a named 1Password item.
- The agent follows the Skill instructions and executes the vulnerable
op item getcommand. - The 1Password CLI emits the complete item record as JSON, including password-bearing fields.
- The execution environment captures standard output in the tool result, transcript, logs, or telemetry.
- An actor with access to those retained outputs can recover and reuse the exposed credentials outside the intended browser session.
Impact Assessment
Successful exploitation can disclose the username, password, login URL, and potentially other fields stored in the selected 1Password item. An exposed password may permit unauthorized access to the associated external account with all privileges granted to that account. If the credential is reused elsewhere, the compromise may extend to addition ...[truncated 256 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not request or return the complete item JSON when only specific fields are needed.
- Retrieve only the minimum required fields through narrowly scoped 1Password CLI options or secret references.
- Avoid merging standard error into standard output for commands that handle secrets.
- Use a protected secret-delivery mechanism that passes credentials directly to the browser without placing them in the agent transcript or general command output.
- Configure execution infrastructure to suppress secret-bearing output, redact known sensitive fields, and prevent such output from entering telemetry or persistent logs.
- Keep credentials in memory only for the duration of the login operation and clear references immediately afterward.
- Use a dedicated, least-privileged 1Password service account that can access only explicitly authorized login items.
