Follow-ups from the credential purge (#112): refusal diagnostics, Key Prefix labels, truncated prefixes in rotation history #113

Open
opened 2026-09-17 07:15:39 +00:00 by abiba-bot · 0 comments
Owner

PR #112 merged (the six committed credentials are out of the working tree). Three follow-ups the review found, plus one thing it flagged that I verified separately.

(1) scripts/agent-health-check.py misattributes a missing credential as a missing secret. With neither INFISICAL_TOKEN nor ~/.infisical-token available, the script now runs to completion and reports the SYMPTOM as vault secret TANKO_LITELLM_API_KEY MISSING or EMPTY / vault-empty:tanko:..., exit 1. It fails closed, so nothing is unsafe - but a reader can interpret "the secret is missing from the vault" as a deleted credential when the real condition is "this host has no vault token". The round-1 line sys.exit(1) with "INFISICAL_TOKEN not set - refusing to run with no credential" was lost in the rewrite; a one-line addition after the file-fallback distinguishes the two cases. The same authoring pattern applies to the other two scripts, which do refuse loudly - check them for consistency.

(2) The same "Key Prefix" label renders a vault path in one place and a synthetic prefix in another. agent-zero-openrouter-key.prose.md:92 still has a table row | **Key Prefix** | «vault: agents/production OPENROUTER_API_KEY» | while line 57 in the same file now shows "sk-or-v1-synthetic..."; litellm-api-keys.prose.md:280 has the same shape under - **Prefix**:. A field that says "prefix" should hold a prefix, with the vault reference in the adjacent field.

(3) Truncated key prefixes remain in the rotation history (pre-existing, not introduced by #112): litellm-api-keys.prose.md:317-319 (sk-_SWAl_Vu_, sk-OzuWsoX2…, sk-6sbCNjz, sk-BqRRMboTI…, sk-krnw_zGB, sk-OEK7z26n6E…), :334 (sk-sxbphLvk1OU…) and hermes-config-template.prose.md:374. Each is a partial value rather than a credential, but they are the same class of leak in miniature and they sit in the document that teaches key hygiene. Replace with synthetic forms and say so.

(4) Verified separately, no action needed: sk-syslog-local-master-key is documented as deprecated and it IS dead - I tested it against the gateway: 401 on both /key/list and /v1/models. So that reference is accurate documentation rather than a live credential.

(5) Still with the captain, not this repo: rotation of the six exposed credentials, and the guard that fails when a credential is committed. Until the guard exists, this class will recur - this PR fixes six instances, not the cause.

PR #112 merged (the six committed credentials are out of the working tree). Three follow-ups the review found, plus one thing it flagged that I verified separately. **(1) `scripts/agent-health-check.py` misattributes a missing credential as a missing secret.** With neither `INFISICAL_TOKEN` nor `~/.infisical-token` available, the script now runs to completion and reports the SYMPTOM as `vault secret TANKO_LITELLM_API_KEY MISSING or EMPTY` / `vault-empty:tanko:...`, exit 1. It fails closed, so nothing is unsafe - but a reader can interpret "the secret is missing from the vault" as a deleted credential when the real condition is "this host has no vault token". The round-1 line `sys.exit(1)` with "INFISICAL_TOKEN not set - refusing to run with no credential" was lost in the rewrite; a one-line addition after the file-fallback distinguishes the two cases. The same authoring pattern applies to the other two scripts, which do refuse loudly - check them for consistency. **(2) The same "Key Prefix" label renders a vault path in one place and a synthetic prefix in another.** `agent-zero-openrouter-key.prose.md:92` still has a table row `| **Key Prefix** | «vault: agents/production OPENROUTER_API_KEY» |` while line 57 in the same file now shows `"sk-or-v1-synthetic..."`; `litellm-api-keys.prose.md:280` has the same shape under `- **Prefix**:`. A field that says "prefix" should hold a prefix, with the vault reference in the adjacent field. **(3) Truncated key prefixes remain in the rotation history** (pre-existing, not introduced by #112): `litellm-api-keys.prose.md:317-319` (`sk-_SWAl_Vu_`, `sk-OzuWsoX2…`, `sk-6sbCNjz`, `sk-BqRRMboTI…`, `sk-krnw_zGB`, `sk-OEK7z26n6E…`), `:334` (`sk-sxbphLvk1OU…`) and `hermes-config-template.prose.md:374`. Each is a partial value rather than a credential, but they are the same class of leak in miniature and they sit in the document that teaches key hygiene. Replace with synthetic forms and say so. **(4) Verified separately, no action needed:** `sk-syslog-local-master-key` is documented as deprecated and it IS dead - I tested it against the gateway: 401 on both `/key/list` and `/v1/models`. So that reference is accurate documentation rather than a live credential. **(5) Still with the captain, not this repo:** rotation of the six exposed credentials, and the guard that fails when a credential is committed. Until the guard exists, this class will recur - this PR fixes six instances, not the cause.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SyslogSolution/prose-contracts#113