T09 · Insecure Skill Coding Practices
- Location
audit.sh:96- Finding
Malformed grep expressions cause security checks to fail open
- Content
View full analysis
/dev/null; then print_fail "Possible OpenAI/API key detected" FOUND_CRITICAL=1 fi if grep -rqE "password\s*=\s*[\"']" . --include="*.md" --include="*.sh" --include="*.js" --include="*.json" 2>/dev/null; then print_fail "Possible hardcoded password detected" FOUND_CRITICAL=1 fi if grep -rqE "api_key\s*=\s*[\"']" . --include="*.md" --include="*.sh" --include="*.js" --include="*.json" 2>/dev/null; then print_fail "Possible hardcoded api_key detected" FOUND_CRITICAL=1 fi if grep -rqE "-----BEGIN.*PRIVATE KEY-----" . --include="*.md" --include="*.sh" 2>/dev/null; then print_fail "Private key found in skill files" FOUND_CRITICAL=1 fi if [[ $FOUND_CRITICAL -eq 0 ]]; then print_pass "No obvious hardcoded secrets found" fi if grep -rqE "http://(?!localhost|127\.0\.0\.1)" . --include="*.md" --include="*.sh" 2>/dev/null; then print_warn "Non-localhost HTTP URL found (consider HTTPS)" fi ``` ### Technical Analysis The private-key search passes a pattern beginning with hyphens directly to `grep`: ```bash grep -rqE "-----BEGIN.*PRIVATE KEY-----" . ``` Without `-e` or an option terminator before the pattern, `grep` may interpret the pattern as command-line options and terminate with an error instead of scanning the files. The external-URL expression uses negative lookahead: ```regex http://(?!localhost|127\.0\.0\.1) ``` The script selects extended regular expressions with `grep -E`, but POSIX extended regular expressions do not support Perl-style negative lookahead. The expression therefore produces an error rather than reliably identifying non-local HTTP URLs. ...[truncated 2259 chars]- Remediation
View remediation
