T09 · Insecure Skill Coding Practices
- Location
scripts/security-audit.sh:21- Finding
Credential Scanner Discloses Detected Secrets in Audit Output
- Content
View full analysis
/dev/null | grep -v "SECURITY" | grep -v "KNOWLEDGE" | grep -v "template" | grep -v "example" || true) if [ -n "$MATCHES" ]; then echo "⚠️ Potential credentials found:" echo "$MATCHES" | head -20 ISSUES=$((ISSUES + 1)) else echo "✅ No leaked credentials detected" fi ``` ### Technical Analysis The scanner is local and read-only, and it contains no network calls. However, `grep` returns the complete matching line, including any credential value, and the script prints up to 20 such lines verbatim. This defeats the expected safety property of a credential scanner: detecting secret locations without redisclosing the secrets. When invoked by an agent through an execution tool, stdout may be copied into a chat response, execution transcript, platform log, telemetry system, or persistent conversation history. A secret originally confined to a local workspace can consequently be duplicated into less trusted storage. The filename exclusion pipeline is not a sufficient mitigation. It omits selected names containing terms such as `SECURITY` and `example`, but it neither redacts matched values nor protects credentials in ordinary Markdown, JSON, YAML, or text files. ### Attack Path 1. A real credential is present in a supported workspace file, such as a JSON configuration or Mar ...[truncated 1194 chars]- Remediation
View remediation
