T09 · Insecure Skill Coding Practices
- Location
SKILL.md:378- Finding
ClickHouse Passwords Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 378 and 403
Vulnerability Type: Credential exposure through process arguments
Risk Level: MediumThe environment-variable and complete-script examples expand ClickHouse passwords directly into the
--passwordcommand-line argument:bash clickhouse-client -h "$CLICKHOUSE_HOST" -u "$CLICKHOUSE_USER" -d "$CLICKHOUSE_DB" --password="$CLICKHOUSE_PASSWORD" -q "SELECT 1;" --format=JSONEachRowbash clickhouse-client -h "$DB_HOST" -u "$DB_USER" --password="$DB_PASS" -d "$DB_NAME" -q "$QUERY" --format=JSON 2>&1 | jq .Technical Analysis
Although the passwords originate in environment variables, shell expansion places their values in the
clickhouse-clientprocess argument vector. Depending on the operating system configuration and diagnostic environment, command-line arguments may be visible through process inspection utilities, process metadata interfaces, audit systems, shell tracing, monitoring agents, or collected diagnostic logs.This guidance also contradicts the security warning at
SKILL.md:408, which correctly states that passwords should not be written on the command line because they can be visible in the process list.An attacker does not need to modify the Skill or inject a command. Exploitation requires the victim to follow one of the affected examples while the attacker or an exposed monitoring system can observe process arguments.
Attack Path
- A user stores a valid ClickHouse password in
CLICKHOUSE_PASSWORDorDB_PASS. - The user runs one of the documented commands.
- The shell expands the variable and passes the plaintext password as part of the process argument vector.
- A local user, monitoring agent, audit subsystem, tracing facility, or diagnostic collector captures the process arguments while the client is running.
- The observer extracts the ClickHouse username, host, database, and password. ...[truncated 1201 chars]
- A user stores a valid ClickHouse password in
- Remediation
View remediation
Remediation Suggestions
- Remove
--password="$CLICKHOUSE_PASSWORD"and--password="$DB_PASS"from all examples. - Use a ClickHouse client authentication mechanism that does not place the secret in the process argument vector.
- Prefer a dedicated ClickHouse client configuration file containing the password, with restrictive permissions:
bash chmod 600 ~/.clickhouse-client/config.xml clickhouse-client --config ~/.clickhouse-client/config.xml -q "SELECT 1;" - If supported by the deployed client version, use its documented environment-based or interactive password mechanism without copying the value into
argv. - Disable shell tracing with
set +xbefore handling credentials, and ensure CI/CD systems and monitoring agents do not record secrets. - Use a dedicated, read-only, least-privilege ClickHouse account for query-only workflows. Use separate narrowly scoped accounts for mutation or administrative tasks.
- Require TLS through
--securefor production connections so credentials and database traffic are protected in transit. - Rotate credentials if the affected examples have been used in environments where process arguments or command telemetry may have been collected.
- Remove
