T09 · Insecure Skill Coding Practices
- Location
scripts/call_mysteel_api.py:40- Finding
Plaintext API Credential Storage in the Project Directory
- Content
View full analysis
Vulnerability Details
File Location:
scripts/call_mysteel_api.py:40-61; related instructions inSKILL.md:23-25, 58-59, 177
Vulnerability Type: Plaintext sensitive-data storage
Risk Level: MediumVulnerable Code
python # API密钥文件路径 api_key_file = os.path.join(skill_root, 'references', 'api_key.md') # 检查文件是否存在 if not os.path.exists(api_key_file): return '' try: with open(api_key_file, 'r', encoding='utf-8') as f: lines = [line.strip() for line in f.readlines() if line.strip()] # 文件至少需要2行(注释行+密钥行) if len(lines) < 2: return '' # 第二行为api_key api_key = lines[1] # 检查是否为占位符 if api_key == 'YOUR_API_KEY_HERE' or not api_key: return '' return api_keyThe associated Skill instructions explicitly require the credential to be written to this file:
text 配置方式:在 `references/api_key.md` 文件中配置(将 `YOUR_API_KEY_HERE` 替换为实际的API密钥)text 用户输入密钥 → 智能体更新`references/api_key.md`文件Technical Analysis
The Skill requires a live Mysteel API credential to be persisted as plaintext in
references/api_key.md, inside the project directory. The implementation reads that credential directly without checking file ownership or permissions, and the project does not provide controls preventing the credential file from being committed, archived, copied, or exposed to other local processes.Sending the credential in the
tokenheader to the declared Mysteel HTTPS endpoint is necessary for authenticated API access and is not itself an unauthorized transmission. The security weakness is the unnecessary persistence of that credential in a source-tree file. Environment variables, a credential manager, or an external permission-restricted configuration location would provide the required authentication capability with less exposure.Exploitation requires an attacker or process to obtain read access to the project dir ...[truncated 1284 chars]
- Remediation
View remediation
Remediation Suggestions
- Read the API key from an environment variable or operating-system secret manager rather than a file in the Skill directory.
- Remove the instruction requiring the Agent to write user-provided credentials into
references/api_key.md. - If file-based configuration must remain available, place the secret outside the repository and accept its path through a secure configuration mechanism.
- Enforce owner-only permissions before reading a credential file and reject files accessible by other users where the platform supports permission checks.
- Add all local secret-file patterns to
.gitignoreand provide only a placeholder template such asapi_key.md.example. - Avoid printing, serializing, or including the credential in diagnostic output or exceptions.
- Document credential revocation and rotation procedures for users who may already have stored or committed a live key.
- Prefer short-lived, narrowly scoped API tokens so disclosure grants only the minimum permissions and duration necessary for report generation.
