T09 · Insecure Skill Coding Practices
- Location
SKILL.md:33- Finding
Credential File Is Executed as Shell Code and the API Token Is Printed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to do what it says, but its setup stores and prints long-lived API credentials in ways that deserve review before installation.
Review this before installing. Use an OS keychain, secret manager, or encrypted vault instead of the plaintext fallback where possible; avoid putting funds in the generated wallet; do not print or paste the token into shell history; and rotate or revoke credentials if they may have been exposed.
SKILL.md:33Credential File Is Executed as Shell Code and the API Token Is Printed
SKILL.md:48Private Key and Non-Expiring API Token Are Persisted in Plaintext
The skill recommends persisting both a Solana private key and a non-expiring API token in a local sourced credentials file. Even with chmod 600, long-lived secrets stored in plaintext on disk materially increase the blast radius of local compromise, backups, accidental inclusion in support bundles, or unsafe sourcing by other scripts.
## Registration
### Step 1: Create a Solana Wallet
Generate a keypair for authentication. **Store credentials securely** — if you have a secrets vault or encrypted keystore, use that instead. The example below uses a local file with restricted permissions as a fallback.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
print(f'AIKEK_ADDRESS={kp.pubkey()}') " > ~/.config/aikek/credentials
chmod 600 ~/.config/aikek/credentials source ~/.config/aikek/credentials
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
message = f"Sign this message to authenticate with AIKEK API.\n\nAddress: {keypair.pubkey()}\nTimestamp: {timestamp}"
signature = keypair.sign_message(message.encode("utf-8"))
response = requests.post(
"https://api.alphakek.ai/auth/wallet-login",
json={"address": str(keypair.pubkey()), "signature": str(signature), "timestamp": timestamp},
)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
message = f"Sign this message to authenticate with AIKEK API.\n\nAddress: {keypair.pubkey()}\nTimestamp: {timestamp}"
signature = keypair.sign_message(message.encode("utf-8"))
response = requests.post(
"https://api.alphakek.ai/auth/wallet-login",
json={"address": str(keypair.pubkey()), "signature": str(signature), "timestamp": timestamp},
)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
signature = keypair.sign_message(message.encode("utf-8"))
response = requests.post(
"https://api.alphakek.ai/auth/wallet-login",
json={"address": str(keypair.pubkey()), "signature": str(signature), "timestamp": timestamp},
)
data = response.json()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
signature = keypair.sign_message(message.encode("utf-8"))
response = requests.post(
"https://api.alphakek.ai/auth/wallet-login",
json={"address": str(keypair.pubkey()), "signature": str(signature), "timestamp": timestamp},
)
data = response.json()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
signature = keypair.sign_message(message.encode("utf-8"))
response = requests.post(
"https://api.alphakek.ai/auth/wallet-login",
json={"address": str(keypair.pubkey()), "signature": str(signature), "timestamp": timestamp},
)
data = response.json()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
signature = keypair.sign_message(message.encode("utf-8"))
response = requests.post(
"https://api.alphakek.ai/auth/wallet-login",
json={"address": str(keypair.pubkey()), "signature": str(signature), "timestamp": timestamp},
)
data = response.json()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
signature = keypair.sign_message(message.encode("utf-8"))
response = requests.post(
"https://api.alphakek.ai/auth/wallet-login",
json={"address": str(keypair.pubkey()), "signature": str(signature), "timestamp": timestamp},
)
data = response.json()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
signature = keypair.sign_message(message.encode("utf-8"))
response = requests.post(
"https://api.alphakek.ai/auth/wallet-login",
json={"address": str(keypair.pubkey()), "signature": str(signature), "timestamp": timestamp},
)
data = response.json()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
signature = keypair.sign_message(message.encode("utf-8"))
response = requests.post(
"https://api.alphakek.ai/auth/wallet-login",
json={"address": str(keypair.pubkey()), "signature": str(signature), "timestamp": timestamp},
)
data = response.json()
The skill instructs users to print a newly issued long-lived API token to stdout and then manually echo it into a credentials file. This increases the chance of credential exposure through terminal scrollback, screen sharing, logging, copy/paste mistakes, or shell history, especially because the token is explicitly described as non-expiring.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Endpoint: POST https://api.alphakek.ai/knowledge/ask
curl -s -X POST https://api.alphakek.ai/knowledge/ask \
-H "Authorization: Bearer $AIKEK_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{"question": "What is the current sentiment on Solana?", "search_mode": "fast"}'
No suspicious patterns detected.