T09 · Insecure Skill Coding Practices
- Location
SKILL.md:63- Finding
Track123 API Key Collected Through Chat and Persisted in Plaintext
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 63–65
Vulnerability Type: Plaintext credential storage and insecure secret handling
Risk Level: MediumRelevant instruction, translated into English:
text API Key configuration (required only for the first use) If the curl command below still contains `$TRACK123_API_KEY`, ask the user to visit https://www.track123.com/api, open Dashboard, select the API tab, copy the key, and paste it here. After receiving it, replace `$TRACK123_API_KEY` in this Skill file with the real key.Technical Analysis
The Skill explicitly instructs the agent to ask the user to paste an API credential into the conversation and then replace the
$TRACK123_API_KEYplaceholder inSKILL.mdwith the actual secret.This creates two insecure copies of the credential:
- The API key is exposed in conversation history and any associated telemetry or logs.
- The API key is permanently embedded in a plaintext project file.
Secrets stored in Skill instructions may subsequently be exposed through repository commits, backups, project archives, file-reading tools, diagnostic output, or later sessions with access to the same workspace. The issue is an insecure coding and configuration practice rather than evidence of an intentionally malicious credential-exfiltration mechanism.
Attack Path
- The Skill detects that
$TRACK123_API_KEYhas not been replaced. - It asks the user to paste a valid Track123 API key into the conversation.
- The user provides the credential, causing it to enter conversation records and potentially platform logs.
- The agent writes the supplied key directly into
SKILL.md. - An attacker or unauthorized user obtains access to the project directory, repository history, backup, shared archive, conversation history, or diagnostic logs.
- The attacker extracts the plaintext API key and uses it to issue requests against the Track ...[truncated 833 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to paste the API key into the conversation or modify
SKILL.md. - Read
TRACK123_API_KEYexclusively from a process environment variable or an approved secret manager at runtime. - Configure the execution environment to inject the secret without exposing it to prompts, generated responses, command output, or source files.
- If a local configuration file is unavoidable, store it outside the Skill package, restrict its filesystem permissions, and exclude it from version control and project archives.
- Avoid printing curl commands with expanded credentials and ensure request headers are redacted from logs and error messages.
- Add automated secret scanning to repository and packaging workflows.
- Rotate any Track123 API key that has already been pasted into a conversation or written into the Skill file, and review API activity for unauthorized use.
- Apply the least privilege and lowest practical quota to the Track123 credential.
- Remove the instruction to paste the API key into the conversation or modify
