T09 · Insecure Skill Coding Practices
- Location
scripts/scan.sh:29- Finding
Detected secrets are disclosed verbatim in scanner output
- Content
View full analysis
Vulnerability Details
File Location:
scripts/scan.sh, lines 29–38; additional affected output logic at lines 75–79
Vulnerability Type: Sensitive information exposure through diagnostic output
Risk Level: HighVulnerable Code:
bash scan_pattern() { local label="$1" pattern="$2" risk="$3" while IFS= read -r line; do local file="${line%%:*}" [[ "$(realpath "$file")" == "$SELF_PATH" ]] && continue echo "${line}:${risk} # ${label}" FOUND=1 done < <(grep -rnI --include='*' -E "$pattern" "$TARGET_DIR" \ --exclude-dir='.git' --exclude-dir='node_modules' \ --exclude-dir='__pycache__' --exclude-dir='.venv' \ --exclude='*.png' --exclude='*.jpg' --exclude='*.ico' \ 2>/dev/null || true) }The same issue occurs when scanning environment files:
bash while IFS= read -r envfile; do while IFS= read -r line; do echo "${line}:HIGH # env-secret" FOUND=1 done < <(grep -nE '^[A-Z_]+\s*=\s*.+' "$envfile" \ | grep -ivE '=(true|false|[0-9]+|""|'\'''\''|\$\{)' 2>/dev/null || true) done < <(find "$TARGET_DIR" -maxdepth 3 -name '.env*' -not -name '.env.example' \ -not -path '*/.git/*' 2>/dev/null || true)Technical Analysis
The scanner uses
grep -norgrep -rnI, both of which return the entire matching source line. The resulting line is then emitted directly withecho. When the match is an API key, password assignment, access token, or environment variable, the sensitive value itself is therefore copied into standard output.This violates secure secret-handling principles because a detection tool should report secret metadata without reproducing the secret. Standard output may be retained in CI logs, terminal capture systems, Agent conversation transcripts, or other audit artifacts. The environment-file branch is especially broad because it prints complete nontrivial assignments from ...[truncated 1185 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not print the complete matching line. Report only the file path, line number, finding label, and severity.
- Use
grep -lor process matches so that sensitive values are replaced with a constant such as[REDACTED]. - For
.envfiles, parse only variable names and emit output such aspath:line:VARIABLE_NAME:[REDACTED]. - Ensure partial masking cannot expose short secrets or enough characters to reconstruct them.
- Document that scanner output must be treated as potentially sensitive until the redaction fix is deployed.
- Add automated tests containing synthetic credentials and verify that no credential value appears in standard output or standard error.
- Consider restrictive handling for generated reports, including limited file permissions and disabled CI artifact retention where practical.
