T09 · Insecure Skill Coding Practices
- Location
SKILL.md:27- Finding
Credential Files Are Created Without Explicitly Restrictive Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 27–29
Vulnerability Type: Plaintext credential storage with environment-dependent file permissions
Risk Level: MediumVulnerable Code
bash mkdir -p ~/.config/ima echo "your_client_id" > ~/.config/ima/client_id echo "your_api_key" > ~/.config/ima/api_keyTechnical Analysis
The setup instructions write the IMA Client ID and App Key to plaintext files without setting a restrictive
umaskor explicitly assigning permissions to the directory and files. The resulting permissions therefore depend on the user's current environment.In an environment with a permissive
umask, other local accounts may be able to traverse the configuration directory and read the credential files. The App Key is a long-lived authentication secret used by the documented API helper to access the user's IMA notes.No hardcoded production credential was found; the vulnerability concerns the insecure credential-storage procedure presented to users.
Attack Path
- A user follows the documented setup procedure.
- The shell creates
~/.config/ima,client_id, andapi_keyusing the environment's default permissions. - On a shared system with permissive permissions, another local account enumerates or directly reads these files.
- The attacker obtains both the Client ID and App Key.
- The attacker supplies the credentials in the documented
ima-openapi-clientidandima-openapi-apikeyHTTP headers. - The attacker invokes the IMA note API as the victim.
This attack requires local access and permissions sufficient to read the affected files; the documented commands do not independently bypass operating-system access controls.
Impact Assessment
Successful exploitation exposes the victim's IMA API credentials. Within the privileges granted to those credentials, an attacker may be able to:
- Search private notes and note content.
- Enumerate notebooks and their note metadata.
- Read priva ...[truncated 300 chars]
- Remediation
View remediation
Remediation Suggestions
Create the configuration directory and credential files with explicit owner-only permissions:
bash install -d -m 700 ~/.config/ima umask 077 printf '%s\n' "your_client_id" > ~/.config/ima/client_id printf '%s\n' "your_api_key" > ~/.config/ima/api_key chmod 600 ~/.config/ima/client_id ~/.config/ima/api_keyAdditional hardening measures:
-
Prefer an operating-system credential manager or secret store over plaintext files.
-
Verify permissions before every API call and reject insecure files:
bash [ "$(stat -c '%a' ~/.config/ima/api_key)" = "600" ] || { echo "Refusing to use an API key with insecure permissions" exit 1 } -
Avoid printing credentials in logs, command traces, errors, or API responses.
-
Document credential rotation and revocation procedures in case the files are exposed.
-
Use narrowly scoped and revocable API credentials when the service supports them.
-
