T09 · Insecure Skill Coding Practices
- Location
examples/token-refresh.sh:15- Finding
OAuth Access Token Disclosed Through Standard Output
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 } ``` 3. If diagnostic output is necessary, print only non-sensitive status information and explicitly redact token fields. 4. Configure agent runtimes, CI systems, and centralized logging tools to mask OAuth tokens and related secrets. 5. Avoid passing the token to downstream processes through command-line arguments, which may be visible in process listings. Prefer protected environment injection, standard input, or a managed secret interface. 6. Restrict access to execution logs and define short retention periods for logs that may already contain credentials. 7. Revoke and rotate any token that may have been exposed by prior script executions. ]]>
