T09 · Insecure Skill Coding Practices
- Location
scripts/media_gen_client.py:506- Finding
Command-Line API Key Handling Exposes Credentials to Local Observation and Logging
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:61;scripts/media_gen_client.py:506
Vulnerability Type: Sensitive credential exposure through command-line arguments
Risk Level: MediumVulnerable Code
SKILL.md:61:markdown - Prefer explicit CLI auth flags when a script exposes them.scripts/media_gen_client.py:506:python p.add_argument("--api-key", help="Override AISA_API_KEY")The API key is subsequently selected from the explicit command-line value or the environment:
python def _get_api_key(explicit: Optional[str] = None) -> str: api_key = explicit or os.environ.get("AISA_API_KEY") if not api_key: raise ValueError("AISA_API_KEY is required (env or --api-key).") return api_keyTechnical Analysis
The client permits the AIsa API key to be supplied as a regular command-line argument, and the Skill documentation explicitly recommends CLI authentication flags. Secrets placed in command-line arguments can be exposed through:
- Shell history files.
- Process listings and process-monitoring utilities.
- CI/CD job metadata and execution logs.
- Terminal session recording.
- Diagnostic or endpoint-monitoring telemetry.
Although environment variables are also imperfect, the project already supports
AISA_API_KEY, making explicit command-line transmission unnecessary for normal operation. Encouraging the CLI option therefore increases credential exposure beyond the minimum needed for media generation.The key is legitimately sent as an HTTPS bearer token to the fixed
api.aisa.oneservice. No evidence was found that the application prints the key or sends it to unrelated destinations.Attack Path
- A user follows the documented recommendation and runs a command such as:
bash python3 scripts/media_gen_client.py --api-key SECRET image --prompt "example" - The complete command is retained in shell history, captured in an automation log, or temporarily exposed through ...[truncated 620 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction in
SKILL.mdthat prefers explicit CLI authentication flags. - Prefer
AISA_API_KEYor a platform-provided secure credential store. - Remove
--api-keyif backward compatibility does not require it. - If the option must remain, document that it is unsafe for shared systems, recorded terminals, and CI/CD environments.
- Consider accepting the credential through a non-echoing interactive prompt or standard input where appropriate.
- Ensure error messages, diagnostics, and debug logging never include request authorization headers.
- Recommend key rotation if a credential has previously been supplied on the command line or retained in logs.
- Remove the instruction in
