T09 · Insecure Skill Coding Practices
- Location
SKILL.md:254- Finding
Hardcoded Unlock Credential in State-Machine Example
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 254–279
Vulnerability Type: Hardcoded plaintext credential
Risk Level: MediumVulnerable Code
erlang -define(CODE, "1234"). start_link() -> gen_statem:start_link({local, ?MODULE}, ?MODULE, [], []). open() -> gen_statem:call(?MODULE, open). close() -> gen_statem:call(?MODULE, close). lock() -> gen_statem:call(?MODULE, lock). unlock(Code) -> gen_statem:call(?MODULE, {unlock, Code}). init([]) -> {ok, locked, #{}}. callback_mode() -> state_functions. %% Locked state locked(call, {unlock, Code}, Data) when Code =:= ?CODE -> {next_state, unlocked, Data, [{reply, ok}]};Technical Analysis
The example embeds the unlock credential
1234directly in source code and compares a caller-supplied value against that constant. Anyone who can inspect the source, documentation, or potentially compiled artifacts can recover the credential. The value cannot be independently rotated without changing and redeploying the code.The comparison also treats knowledge of a reusable plaintext value as sufficient authorization. It provides no per-user authentication, rate limiting, replay protection, credential hashing, authorization policy, or audit controls.
This file is instructional documentation rather than a directly executable application. Therefore, exploitation requires a developer to copy or adapt the example into a deployed system without replacing the placeholder authentication mechanism.
Attack Path
- A developer copies the documented
door_fsmexample into an application. - The fixed
CODEvalue remains unchanged in the deployed implementation. - An attacker reads the public example, obtains leaked source, or extracts the constant from an accessible artifact.
- The attacker submits
unlock("1234")through an exposed application interface that reachesgen_statem:call/2. - The guard evaluates successfully and transitions the state ma ...[truncated 823 chars]
- A developer copies the documented
- Remediation
View remediation
Remediation Suggestions
- Mark the credential and state-machine implementation explicitly as a non-production demonstration.
- Remove the fixed plaintext value from source code.
- Load authentication configuration at runtime from an approved secret manager or protected configuration source.
- Store and compare a password verifier produced by a suitable password-hashing algorithm rather than retaining the plaintext credential.
- Restrict access to the unlock API and apply authorization independently of possession of a shared code.
- Add failed-attempt throttling, temporary lockout, monitoring, and security audit logging.
- Use constant-time comparison where secret comparison remains necessary.
- Establish a credential-rotation process that does not require source changes.
- Add a secure production-oriented example demonstrating secret injection and access control so users are less likely to copy the insecure placeholder unchanged.
