T09 · Insecure Skill Coding Practices
- Location
references/troubleshooting.md:44- Finding
Hard-Coded Private Nexus Repository Credentials
- Content
View full analysis
link-nexus linkcrm hand123654 ``` ### Technical Analysis The troubleshooting guide embeds a Nexus username and password directly in a Maven configuration example. The surrounding instructions direct users to place this configuration into `settings.xml`, making the exposed values operationally reusable rather than merely descriptive. Secrets stored in Skill packages are accessible to anyone who can read the package, its distribution archive, source-control history, or generated audit artifacts. Maven server credentials may be sent automatically whenever Maven connects to a repository whose server identifier is `link-nexus`. ### Attack Path 1. An attacker obtains read access to the Skill package or repository. 2. The attacker extracts the username and password from `references/troubleshooting.md`. 3. The attacker authenticates to the internal Nexus service if it is network-accessible. 4. Depending on the account permissions, the attacker downloads proprietary artifacts or enumerates repository contents. 5. If the account has publication privileges, the attacker uploads or replaces artifacts. 6. Developers subsequently retrieve the modified artifacts during Maven builds, potentially propagating malicious code into application packages and container images. ### Impact Assessment The immediate scope is the Nexus account represented by the exposed credentials. Potential consequences include unauthorized access to proprietary dependencies, disclosure of internal package metadata, credential reuse attacks, and supply-chain compromise. If the account has write or deployment privileges, an attacker could tamper with private dependencies and affect every application tha ...[truncated 93 chars]- Remediation
View remediation
