T09 · Insecure Skill Coding Practices
- Location
SKILL.md:277- Finding
Plaintext Persistence of Binance API Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:277-296, 311-315
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: HighThe skill explicitly instructs the agent to store newly supplied Binance API credentials in
TOOLS.md. The prescribed file structure includes complete API keys and secrets:markdown ### TOOLS.md Structure ```bash ## Binance Accounts ### main - API Key: abc123...xyz - Secret: secret123...key - Testnet: false - Description: Primary trading account ### testnet-dev - API Key: test456...abc - Secret: testsecret...xyz - Testnet: true - Description: Development/testing ### futures-keys - API Key: futures789...def - Secret: futuressecret...uvw - Testnet: false - Description: Futures trading accounttext The storage instruction is: ```markdown ## Adding New Accounts When user provides new credentials: * Ask for account name * Ask: Mainnet, Testnet or Demo * Store in `TOOLS.md` with masked display confirmationTechnical Analysis
The documented masking requirement applies only to displaying credentials. It does not protect the credentials stored in
TOOLS.md. The skill does not require encryption, an operating-system keychain, a dedicated secret manager, restrictive file permissions, repository exclusion, or access auditing.Consequently, the credential file could be exposed to other local users or processes, backups, synchronization systems, diagnostic collection, or accidental source-control commits. Because Binance signatures are generated using the stored secret, disclosure of both the API key and secret enables an attacker to authenticate independently of the skill.
Attack Path
- A user supplies a Binance API key and secret to the agent.
- Following
SKILL.md, the agent writes the complete credentials intoTOOLS.md. - The file is read through local compromise, excessive filesystem permissions, backup or synchronization exposure, or accidental repository publication.
- The ...[truncated 839 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not store API keys or signing secrets directly in
TOOLS.md. - Store secrets in an operating-system keychain, hardware-backed keystore, or dedicated secret manager. Keep only account aliases and opaque secret references in Markdown configuration.
- If file-based storage is unavoidable:
- Encrypt credentials at rest with a key stored separately.
- Create the file with owner-only permissions, such as mode
0600. - Explicitly exclude the file from source control and packaging.
- Prevent inclusion in logs, backups, diagnostics, and synchronization systems where possible.
- Validate that imported Binance keys have only the minimum required permissions. Reject or prominently warn about withdrawal-enabled credentials.
- Recommend and verify Binance IP allowlisting where operationally possible.
- Separate testnet, demo, and mainnet credentials and make mainnet use explicit.
- Ensure masking is applied to all output, logs, errors, traces, and tool-call records—not merely user-facing confirmation messages.
- Document a credential-rotation and revocation procedure for suspected exposure.
- Do not store API keys or signing secrets directly in
