T09 · Insecure Skill Coding Practices
- Location
shared/cross_model_verification.md:191- Finding
Google API Key Exposed in a Command-Line URL
- Content
View full analysis
Vulnerability Details
File Location:
shared/cross_model_verification.md:191-192
Vulnerability Type: API credential exposure through a URL query parameter
Risk Level: MediumVulnerable Code
bash curl -s "https://generativelanguage.googleapis.com/v1beta/models/${ARS_CROSS_MODEL}:generateContent?key=$GOOGLE_AI_API_KEY" \ -H "Content-Type: application/json" \Technical Analysis
The documented Gemini request interpolates
GOOGLE_AI_API_KEYdirectly into the request URL. When this command is executed, the expanded credential can be exposed through operating-system process inspection, shell tracing or diagnostic output, proxy and gateway logs, HTTP client telemetry, and monitoring products that record URLs.Although HTTPS encrypts the request in transit, it does not prevent disclosure at the endpoint, process, shell, or logging layers. Query strings are also more likely to be retained than authentication headers. The package does not contain a hardcoded key; exploitation requires a user to configure a valid key and execute the documented optional cross-model workflow.
Attack Path
- A user configures
GOOGLE_AI_API_KEYand selects a Gemini model throughARS_CROSS_MODEL. - The cross-model verification workflow executes the documented
curlrequest. - The shell expands
$GOOGLE_AI_API_KEYinto the command-line URL. - A local process observer, shell-debug trace, proxy, telemetry agent, or URL-logging system records the expanded URL.
- An attacker with access to that record extracts the API key.
- The attacker uses the key against enabled Google APIs until it is revoked or constrained by provider-side restrictions.
Impact Assessment
Successful exploitation can disclose the configured Google API credential. The attacker could consume the associated API quota, incur charges, access services authorized for that key, or disrupt legitimate verification through quota exhaustion.
The resulting privileges are limite ...[truncated 230 chars]
- A user configures
- Remediation
View remediation
Remediation Suggestions
- Replace the raw
curlexample with a maintained Google SDK or another client that supports protected credential handling. - Where the API supports it, transmit credentials through an authentication header rather than a query parameter.
- If this endpoint necessarily requires the
keyquery parameter, avoid placing the expanded key in command-line arguments. Construct and execute the request within a process using an HTTP library so the complete URL is not exposed through the process list. - Disable shell tracing around credential-bearing operations and ensure errors never print the complete request URL.
- Configure proxies, gateways, telemetry systems, and application logs to redact query strings and known credential parameters such as
key. - Recommend provider-side API, project, application, quota, and billing restrictions for the key.
- Rotate the key immediately if command history, process telemetry, debug output, or proxy logs may have captured it.
- Add an explicit warning to the setup guide that API credentials must not be committed, printed, or included in diagnostic reports.
- Replace the raw
