T09 · Insecure Skill Coding Practices
- Location
scripts/cos_node.mjs:33- Finding
Credential Encryption Uses Predictable Non-Secret Key Material
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real Tencent COS helper, but it deserves review because it can mutate cloud storage and locally store or decrypt powerful credentials with weakly protected persistence.
Install only if you are comfortable giving an agent Tencent COS/CI authority. Use short-lived STS credentials and a least-privilege sub-account limited to test buckets where possible. Avoid --persist and decrypt-env in shared or logged workspaces, do not rely on .env.enc as strong encryption, and require manual review before delete, delete-multiple, ACL/CORS, dataset binding, or ci-request actions.
scripts/cos_node.mjs:33Credential Encryption Uses Predictable Non-Secret Key Material
scripts/setup.sh:199Setup Installs an Unpinned npm Dependency
The skill is described primarily as a COS/CI operations integration, but the visible content heavily emphasizes local bootstrap behavior such as dependency installation, environment setup, credential persistence, and local secret encryption/decryption. This mismatch can mislead users and reviewers about the actual trust boundary, especially because local shell execution and credential storage are materially riskier than ordinary remote API calls.
Referenced artifact was not completely inspected
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。
Referenced artifact was not completely inspected
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。
Referenced artifact was not completely inspected
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。
Referenced artifact was not completely inspected
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。
Referenced artifact was not completely inspected
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。
Referenced artifact was not completely inspected
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。
Referenced artifact was not completely inspected
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。
The skill explicitly supports persisting cloud credentials to a local .env file. Even with permission controls and optional later encryption, writing plaintext credentials to disk materially increases exposure through local compromise, backups, editor history, accidental disclosure, and operational mistakes.
{baseDir}/scripts/setup.sh --from-env
{baseDir}/scripts/setup.sh --from-env --persist
Advertising encrypt-env and decrypt-env as built-in credential-management actions confirms the skill handles local secret material beyond transient use. In particular, a decrypt capability increases the chance that plaintext credentials are recreated on disk during routine agent operation, widening the exposure window.
| | `upload` → 指向知识库桶 | "上传到知识库" → 上传文档 |
| | `hybrid-search` → 指向知识库数据集 | "查询知识库" → 语义检索文档内容 |
| **🚫 禁止** | ~~deleteBucket~~ | **不允许删除/清空存储桶** |
| **🔐 凭证管理** | `encrypt-env` | 加密 .env → .env.enc 并删除明文 |
| | `decrypt-env` | 解密 .env.enc → .env 还原明文 |
## 安全注意事项
The presence of a documented decryption path for .env.enc back to .env reinforces that the skill is designed to materialize sensitive credentials into plaintext locally. That capability is risky in shared workspaces or automated environments because it normalizes turning encrypted secrets back into broadly accessible files.
| | `hybrid-search` → 指向知识库数据集 | "查询知识库" → 语义检索文档内容 |
| **🚫 禁止** | ~~deleteBucket~~ | **不允许删除/清空存储桶** |
| **🔐 凭证管理** | `encrypt-env` | 加密 .env → .env.enc 并删除明文 |
| | `decrypt-env` | 解密 .env.enc → .env 还原明文 |
## 安全注意事项
The documented encryption scheme stores credentials in .env.enc and derives the key from predictable host/user/path material (SHA-256(hostname + username + project path)) rather than a high-entropy secret. This is not a robust secret-management design: an attacker with knowledge of the environment can likely reproduce the key, defeating the claimed protection and creating a false sense of safety around stored cloud credentials.
- 密钥派生:`SHA-256(hostname + username + 项目绝对路径)`
- **加密文件绑定当前机器和用户**,拷贝到其他机器/用户无法解密
- 如需还原明文:`node scripts/cos_node.mjs decrypt-env`
- 清理凭证:`rm -f .env .env.enc`
**其他安全要求**:
- **永远不要在对话中回显** SecretId/SecretKey
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
// ========== 凭证加解密工具 ==========
const __dirname = dirname(fileURLToPath(import.meta.url));
const envPath = resolve(__dirname, "..", ".env");
const envEncPath = resolve(__dirname, "..", ".env.enc");
// 基于机器特征派生 AES-256 密钥(hostname + username + 项目绝对路径)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
// ========== 凭证加解密工具 ==========
const __dirname = dirname(fileURLToPath(import.meta.url));
const envPath = resolve(__dirname, "..", ".env");
const envEncPath = resolve(__dirname, "..", ".env.enc");
// 基于机器特征派生 AES-256 密钥(hostname + username + 项目绝对路径)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
// ========== 凭证加解密工具 ==========
const __dirname = dirname(fileURLToPath(import.meta.url));
const envPath = resolve(__dirname, "..", ".env");
const envEncPath = resolve(__dirname, "..", ".env.enc");
// 基于机器特征派生 AES-256 密钥(hostname + username + 项目绝对路径)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 用法:
# setup.sh --check-only 仅检查环境状态
# setup.sh --from-env 从已有环境变量读取凭证并安装依赖(不持久化)
# setup.sh --from-env --persist 从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
# - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 用法:
# setup.sh --check-only 仅检查环境状态
# setup.sh --from-env 从已有环境变量读取凭证并安装依赖(不持久化)
# setup.sh --from-env --persist 从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
# - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 用法:
# setup.sh --check-only 仅检查环境状态
# setup.sh --from-env 从已有环境变量读取凭证并安装依赖(不持久化)
# setup.sh --from-env --persist 从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
# - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 用法:
# setup.sh --check-only 仅检查环境状态
# setup.sh --from-env 从已有环境变量读取凭证并安装依赖(不持久化)
# setup.sh --from-env --persist 从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
# - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 用法:
# setup.sh --check-only 仅检查环境状态
# setup.sh --from-env 从已有环境变量读取凭证并安装依赖(不持久化)
# setup.sh --from-env --persist 从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
# - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 用法:
# setup.sh --check-only 仅检查环境状态
# setup.sh --from-env 从已有环境变量读取凭证并安装依赖(不持久化)
# setup.sh --from-env --persist 从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
# - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 用法:
# setup.sh --check-only 仅检查环境状态
# setup.sh --from-env 从已有环境变量读取凭证并安装依赖(不持久化)
# setup.sh --from-env --persist 从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
# - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 用法:
# setup.sh --check-only 仅检查环境状态
# setup.sh --from-env 从已有环境变量读取凭证并安装依赖(不持久化)
# setup.sh --from-env --persist 从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
# - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 用法:
# setup.sh --check-only 仅检查环境状态
# setup.sh --from-env 从已有环境变量读取凭证并安装依赖(不持久化)
# setup.sh --from-env --persist 从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
# - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 用法:
# setup.sh --check-only 仅检查环境状态
# setup.sh --from-env 从已有环境变量读取凭证并安装依赖(不持久化)
# setup.sh --from-env --persist 从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
# - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘
No suspicious patterns detected.