T09 · Insecure Skill Coding Practices
- Location
scripts/setup.js:158- Finding
API Credentials Stored Without Restrictive File Permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/setup.js, lines 158–159
Vulnerability Type: API credential exposure through insecure file permissions
Risk Level: MediumVulnerable Code
js if (!fs.existsSync(CONFIG_DIR)) fs.mkdirSync(CONFIG_DIR, { recursive: true }); fs.writeFileSync(CONFIG_FILE, JSON.stringify(config, null, 2));Technical Analysis
The setup script stores provider API keys in
~/.chinese-llm-router/config.json. It does not specify restrictive permissions when creating either the configuration directory or the file.Consequently, the effective permissions depend on the process umask. In an environment with a permissive umask, the configuration may be readable by other local users. If the file already exists with unsafe permissions, the script also does not correct those permissions when overwriting it.
The stored configuration contains bearer credentials that authorize requests to paid external LLM services. Although no deliberate credential exfiltration was identified, insecure local storage can disclose those credentials to another local principal.
Attack Path
- A user runs
node scripts/setup.js. - The user enters one or more provider API keys.
- The script writes the keys to
~/.chinese-llm-router/config.jsonwithout setting an explicit file mode. - A permissive umask or pre-existing unsafe permissions leave the file readable by another local user or process.
- The attacker reads the configuration and extracts the provider API keys.
- The attacker uses the credentials to make authorized requests against the affected provider accounts.
Impact Assessment
Exploitation requires local filesystem access and permissions sufficient to read the configuration file. A successful attacker may obtain the same provider API authorization represented by the stolen keys, potentially allowing:
- Unauthorized consumption of paid API quotas or credits.
- Acces ...[truncated 261 chars]
- A user runs
- Remediation
View remediation
Remediation Suggestions
- Create the configuration directory with mode
0700. - Create and maintain the configuration file with mode
0600. - Correct permissions on existing directories and files before reading or updating them.
- Write updates atomically through a securely created temporary file in the same directory.
- Reject symbolic links and verify that the destination is a regular file owned by the current user.
- Prefer an operating-system credential manager or secret store instead of plaintext JSON when available.
Example hardening:
js fs.mkdirSync(CONFIG_DIR, { recursive: true, mode: 0o700 }); fs.chmodSync(CONFIG_DIR, 0o700); fs.writeFileSync(CONFIG_FILE, JSON.stringify(config, null, 2), { mode: 0o600, flag: 'w' }); fs.chmodSync(CONFIG_FILE, 0o600);- Create the configuration directory with mode
