T09 · Insecure Skill Coding Practices
- Location
SKILL.md:20- Finding
API Key Stored in Plaintext Configuration File
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20–22
Vulnerability Type: Plaintext secret storage in local configuration
Risk Level: MediumVulnerable Code Snippet
markdown ## Usage 1. Configure API key in `config.json` 2. Place PDF files in `input_pdfs/` folderLine 39 further defines the configuration value:
markdown - `openai_api_key`: Your API key (required)Technical Analysis
The documented setup directs users to place an OpenAI or Kimi API key in
config.json. It does not prescribe environment variables, an operating-system credential store, restrictive file permissions, source-control exclusions, or another secret-management mechanism.A plaintext configuration file can be unintentionally committed to source control, included in backups or diagnostic archives, copied during project sharing, or read by another account with local file access. The implementation files are absent from the audited artifact, so whether any undocumented protections exist cannot be verified.
Attack Path
- A user follows the documented setup and writes a valid API key into
config.json. - The configuration file is committed to a repository, included in a backup or support archive, or exposed to another local user.
- An attacker extracts the plaintext key.
- The attacker submits requests to the corresponding API under the victim's account.
- The key remains usable until it is revoked or restricted by the provider.
Impact Assessment
Exploitation grants the attacker the API permissions assigned to the exposed key. Potential impact includes unauthorized model usage, financial charges, consumption of quotas, access to provider resources available to that credential, and account abuse attributable to the victim. This finding does not establish operating-system privilege escalation.
- A user follows the documented setup and writes a valid API key into
- Remediation
View remediation
Remediation Suggestions
- Read API credentials from environment variables or a supported secret manager rather than
config.json. - Provide a sanitized
config.example.jsoncontaining placeholders only. - Add
config.jsonand other credential-bearing files to.gitignore. - Validate at startup that placeholder or empty credentials are rejected without printing the key.
- Ensure logs and error messages redact API keys.
- Document restrictive local permissions, such as owner-only read/write access.
- Recommend provider-side restrictions, usage limits, monitoring, and periodic rotation.
- If a key has previously been committed, revoke and rotate it; deleting it only from the latest revision does not remove it from repository history.
- Read API credentials from environment variables or a supported secret manager rather than
