T09 · Insecure Skill Coding Practices
- Location
pihole.sh:91- Finding
Pi-hole API Password Exposed Through Process Arguments
- Content
View full analysis
/dev/null) ``` ### Technical Analysis The API password is read from an environment variable or configuration file, but the shell interpolates it into curl's `-d` argument. Consequently, the expanded JSON document containing the password becomes part of curl's process argument vector while authentication is in progress. Depending on operating-system process visibility controls, another process running under the same account—or a privileged local process—may inspect the curl command line and recover the credential. Passing a secret through an environment variable initially does not prevent this exposure after the shell expands it into a command-line argument. This behavior contradicts the claims in `SKILL.md` and `SECURITY_AUDIT.md` that the token is not visible in the process list. ### Attack Path 1. A user invokes a Pi-hole command that requires an authenticated API request. 2. `get_session` expands `PIHOLE_API_TOKEN` into the JSON supplied through curl's `-d` option. 3. Curl runs with the expanded password in its process argument vector. 4. A local process with sufficient process-inspection access reads the curl command line during this interval. 5. The attacker extracts the Pi-hole app password. 6. The attacker authenticates directly to the Pi-hole API and performs operations allowed by that credential. ### Impact Assessment An attacker who obtains the credential may acquire the API privileges assigned to the Pi-hole app password. Based on the Skill's documented capabilities, this can include: - Inspecting Pi-hole status and statistics. - Accessin ...[truncated 383 chars]- Remediation
View remediation
/dev/null ) unset auth_payload ``` Use a Bash array for curl options instead of a space-delimited string to preserve argument boundaries safely. ]]>
