T09 · Insecure Skill Coding Practices
- Location
scripts/skulk-email.sh:43- Finding
Mailbox Passwords Exposed Through Process Command-Line Arguments
- Content
View full analysis
/cmdline`, process-monitoring utilities, audit systems, or diagnostic tooling. The exact accessibility of another process's argument vector depends on host configuration and user privileges. Nevertheless, command-line arguments are not an appropriate secret-transfer mechanism because they create an additional disclosure surface that is unnecessary for the declared email functionality. Although the subsequent IMAP authentication uses TLS, transport encryption does not mitigate local disclosure before the password reaches the network connection. ### Attack Path 1. A local attacker obtains the ability to inspect processes belonging to the Skill's user, such as through a compromised process running under the same account, permissive `/proc` configuration, debugging privileges, or elevated local access. 2. The victim invokes an IMAP-backed command such as `inbox`, `read`, `search`, or a Gmail command. 3. The script starts Python with the mailbox password embedded in its argument vector. 4. The attacker monitors process creation or reads the relevant process command line before Python exits. 5. The attacker extracts the DreamHost mailbox password or Gmail application password. 6. The recovered credential is used to authenticate independently to the corresponding mailbox. ### Impact Assessment Successful exploitation exposes the credentials of the mailbox involved in the command. Depending on ...[truncated 474 chars]- Remediation
View remediation
