T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:8- Finding
Overprivileged Access to Sensitive API Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 8
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: MediumComplete Code Snippet:
yaml environment_variables: ["MARKET_DATA_API_KEY", "OPENAI_API_KEY"]Technical Analysis
The skill requests direct access to two sensitive environment variables. Its documented function is market analysis, but it provides no implementation demonstrating a legitimate need to access the raw
OPENAI_API_KEY. Direct credential exposure violates least-privilege and secret-isolation principles.The current skill text does not instruct the agent to read, disclose, or transmit these credentials. Therefore, this is an excessive-permission risk rather than evidence of active credential theft. Nevertheless, direct secret availability increases the consequences of future prompt injection, unauthorized modification, or compromise of the skill.
Attack Path
- The host grants the environment-variable permissions declared by the skill.
- The skill gains access to the raw market-data and OpenAI API credentials.
- An attacker injects instructions through untrusted market content or modifies the skill after deployment.
- The compromised instructions access one or both environment variables.
- The credentials are disclosed through generated output or transmitted through an allowed network channel.
- The attacker uses the exposed credentials subject to their account-level scopes and provider controls.
This path is conditional: the reviewed file contains no instruction that performs these actions.
Impact Assessment
Successful exploitation could expose the API privileges associated with
MARKET_DATA_API_KEYandOPENAI_API_KEY. Depending on provider-side scopes, quotas, and account configuration, this could enable unauthorized API consumption, financial charges, quota exhaustion, access to provider resources available to the k ...[truncated 332 chars]- Remediation
View remediation
Remediation Suggestions
- Remove
OPENAI_API_KEYfrom the declared environment variables unless a documented, indispensable use case exists. - Do not expose raw credentials to the skill context. Route requests through a narrowly scoped host-side broker or dedicated market-data tool.
- If market-data authentication is required, issue a dedicated credential with read-only access, restricted endpoints, low quotas, and no administrative privileges.
- Enforce destination allowlists at the network layer rather than relying only on prompt instructions.
- Prevent environment-variable values from appearing in model context, logs, error messages, tool results, or generated output.
- Add automatic secret redaction, usage monitoring, spending limits, short expiration periods, and regular credential rotation.
- Document the specific purpose and minimum scope of every requested permission and reject execution when unnecessary permissions are declared.
- Remove
