T09 · Insecure Skill Coding Practices
- Location
SKILL.md:39- Finding
API Key May Be Exposed Through Full Credential File Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 39-48
Vulnerability Type: Credential disclosure through unsafe operational instructions
Risk Level: Mediummarkdown This skill requires an API key. The API key is stored in the `~/.upkuajing/.env` file: ```bash cat ~/.upkuajing/.envExample file content:
text UPKUAJING_API_KEY=your_api_key_hereAPI Key Not Set
First check if the
~/.upkuajing/.envfile has UPKUAJING_API_KEY;text ### Technical Analysis The Skill instructs the Agent to display the complete contents of a plaintext credential file with `cat`. Although reading the dedicated API key is necessary to authenticate requests, printing the file is unnecessary and violates least-disclosure principles. Command output may become visible in terminal history, execution logs, Agent context, captured transcripts, monitoring systems, or user-facing responses. The file could also contain additional environment variables beyond the documented API key, causing disclosure of unrelated secrets. The Python implementation can already obtain the required value directly from the process environment or parse the named variable from the file. Consequently, displaying the complete file exceeds the minimum access required for the declared shareholder-query functionality. ### Attack Path 1. A valid API key is stored in `~/.upkuajing/.env`. 2. The Agent follows the Skill instruction and executes `cat ~/.upkuajing/.env`. 3. The complete plaintext file enters command output and potentially the Agent's context, logs, or transcript. 4. A party with access to those records obtains the API key. 5. The exposed Bearer token is reused to access authenticated UpKuaJing operations or consume paid API services. ### Impact Assessment Exposure grants the privileges associated with the affected UpKuaJing API key. Depending on the account configuration, an attacker could perform authenticated ...[truncated 195 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to run
cat ~/.upkuajing/.env. - Check only whether
UPKUAJING_API_KEYexists, without printing its value. - Prefer passing the key through the process environment rather than reading a plaintext file.
- If file fallback remains necessary, parse only the named variable internally and never include its value in output, logs, errors, or Agent-visible context.
- Document that credential values must be redacted from troubleshooting output.
- Consider using an operating-system credential store or secret manager instead of a plaintext
.envfile.
- Remove the instruction to run
