T09 · Insecure Skill Coding Practices
- Location
scripts/tiger_client.py:195- Finding
Brokerage Private Key Exposure Through Command-Line Arguments and Agent-Generated Content
- Content
View full analysis
Vulnerability Details
File Location:
scripts/tiger_client.py:195,222; additionally documented inSKILL.md:17,35-42
Vulnerability Type: Sensitive credential exposure
Risk Level: HighVulnerable Code and Documentation
scripts/tiger_client.py:195accepts either a private-key path or the complete private-key contents as a command-line argument:python parser.add_argument('--private-key', required=True, help='私钥路径或内容')scripts/tiger_client.py:222then passes that command-line value to the trading client:python client = TigerClient(args.tiger_id, args.account, args.license, args.private_key)SKILL.md:17explicitly instructs users that they can provide private-key contents:markdown - `private_key`: 私钥内容或私钥文件路径SKILL.md:35-42demonstrates embedding private-key material directly in application code:python # 方式2: 使用私钥内容 client = TigerClient( tiger_id='YOUR_TIGER_ID', account='YOUR_ACCOUNT_ID', license='TBNZ', private_key='MIICXAIBAAKBgQ...' )Technical Analysis
A brokerage private key is an authentication secret that must not be placed in command-line arguments, generated source code, conversations, or other routinely retained plaintext channels.
The CLI's
--private-keyoption accepts complete private-key contents. Command-line arguments may be recorded in shell history, process-monitoring systems, terminal logs, job execution records, or operating-system process metadata. Because this project is distributed as an AI Agent Skill, instructions encouraging users to provide key contents also create a risk that the key will be pasted into an Agent conversation or embedded in Agent-generated code. Conversations and generated files may subsequently be retained, synchronized, audited, or exposed to users and services that should not possess the trading credential.Although the implementation also supports a private-key file ...[truncated 1410 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove support for supplying complete private-key contents through command-line arguments. Make
--private-keyaccept only a file path, or replace it with an explicitly named option such as--private-key-file. - Prefer retrieval from an operating-system keychain, hardware-backed key store, protected file descriptor, or established secret-management service.
- Update
SKILL.mdto warn users never to paste brokerage private keys into Agent conversations, prompts, shell commands, or source code. - Remove the direct private-key-content example and replace it with a protected file or secret-manager example.
- Validate private-key file ownership and permissions before use, rejecting files accessible to unauthorized users where the platform supports such checks.
- Ensure application and SDK errors are sanitized so that private-key contents and sensitive configuration cannot be included in returned exception messages or logs.
- Document credential rotation and revocation procedures, and advise users to rotate any key previously supplied through a conversation or command-line argument.
- If non-file secret input is essential, read it from a non-echoing interactive prompt or protected standard input rather than from process arguments, while ensuring that automation systems do not log the input stream.
- Remove support for supplying complete private-key contents through command-line arguments. Make
