T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_stars.py:329- Finding
GitHub Personal Access Token Exposed Through Command-Line Arguments
- Content
View full analysis
[--token ] [--output ] Examples: python3 fetch_stars.py blckrabbit python3 fetch_stars.py https://github.com/blckrabbit?tab=stars python3 fetch_stars.py blckrabbit --token ghp_xxx --output report.md """ ``` ```python def fetch_starred(username: str, token: str = None) -> list: """Call the GitHub API and retrieve all starred repositories page by page.""" headers = {"Accept": "application/vnd.github.star+json"} if token: headers["Authorization"] = f"Bearer {token}" ``` ```python parser.add_argument("--token", default=None, help="GitHub Personal Access Token (optional)") ``` The Skill documentation also directs users to provide a token through the same command-line option: ```bash python3 /home/claude/fetch_stars.py USERNAME --output /home/claude/USERNAME_github_stars.md ``` ```text --token : GitHub Personal Access Token ``` ### Technical Analysis The script accepts a GitHub Personal Access Token directly through the `--token` command-line argument. Command-line arguments are commonly observable through shell history, process inspection utilities, terminal transcripts, orchestration logs, and AI Agent tool-call records. The script uses the credential as an `Authorization: Bearer` header and sends it to the official HTTPS endpoint at `api.github.com`. This network transmission is consistent with the declared authenticated GitHub API functionality and does not constitute evidence of exfiltration to an unauthorized party. The security issue is the method used to ingest the credential before transmission. The authenticated request itself does not exceed the functional ...[truncated 1441 chars]- Remediation
View remediation
