T09 · Insecure Skill Coding Practices
- Location
SKILL.md:271- Finding
Documentation Recommends Printing the API Token to Standard Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 271
Vulnerability Type: Credential disclosure through insecure diagnostic guidance
Risk Level: LowEvidence
markdown > Self-check: This is usually because `GUAIKEI_API_TOKEN` did not pass validation (see Q1). Before running, use `echo $GUAIKEI_API_TOKEN` to confirm that the variable has been injected.Technical Analysis
The troubleshooting instructions recommend printing the complete
GUAIKEI_API_TOKENvalue to standard output. Terminal output is frequently retained in shell transcripts, CI/CD job logs, remote-support recordings, agent execution histories, and centralized logging systems.Although the application code does not print the token itself, following the documented diagnostic procedure can disclose the credential to users or systems that can read captured output. The token is subsequently used as the
TOKENauthentication header forwww.guaikei.com, so disclosure could enable unauthorized use of the associated API account.Attack Path
- A user encounters token validation or authentication failure.
- The user follows the documented troubleshooting instruction and runs
echo $GUAIKEI_API_TOKEN. - The full token appears in terminal output.
- A CI log collector, support-session participant, terminal recorder, or another party with access to execution history obtains the token.
- The party sends requests to the GuaiKei API using the disclosed value in the
TOKENheader. - The token remains usable until it expires or is revoked.
Impact Assessment
Successful exploitation does not grant local operating-system privileges. It grants the external API permissions associated with the compromised token. Depending on server-side authorization and quotas, an attacker could consume API credits, retrieve data available to the account, trigger rate limits, or cause charges and service disruption. The scope is limited to th ...[truncated 45 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the instruction to print the token value.
-
Recommend presence-only checks that do not disclose the secret, for example:
sh test -n "$GUAIKEI_API_TOKEN" && echo "GUAIKEI_API_TOKEN is configured" || echo "GUAIKEI_API_TOKEN is missing" -
If format diagnostics are necessary, perform them inside the application and report only whether validation succeeded.
-
Do not display even partial token values unless a carefully reviewed masked identifier is operationally necessary.
-
Add guidance to rotate the token immediately if it has been printed into a persistent or shared log.
-
Ensure CI/CD systems register the variable as a secret and apply output masking.
-
