T09 · Insecure Skill Coding Practices
- Location
scripts/refresh_token.sh:26- Finding
OAuth Access and Refresh Tokens Exposed in Standard Output
- Content
View full analysis
Vulnerability Details
File Location:
scripts/refresh_token.sh, lines 26–32
Vulnerability Type: Plaintext sensitive credential exposure
Risk Level: HighVulnerable Code
bash if [ -n "$NEW_ACCESS_TOKEN" ]; then echo "✓ Token refreshed successfully" echo "New access token: $NEW_ACCESS_TOKEN" echo "New refresh token: $NEW_REFRESH_TOKEN" echo "Expires at: $(date -r "$EXPIRES_AT" 2>/dev/null || date -d "@$EXPIRES_AT" 2>/dev/null || echo "$EXPIRES_AT")" echo "" echo "Update your config with:" echo " STRAVA_ACCESS_TOKEN=\"$NEW_ACCESS_TOKEN\"" echo " STRAVA_REFRESH_TOKEN=\"$NEW_REFRESH_TOKEN\""Technical Analysis
After a successful OAuth refresh, the script prints the complete access token and refresh token to standard output twice. OAuth bearer tokens must be treated as passwords because possession is sufficient for API authentication.
Standard output can be retained in agent transcripts, terminal-capture systems, CI/CD logs, process-supervisor logs, support bundles, or other centralized logging infrastructure. Consequently, systems and users that are authorized to view operational output—but are not authorized to access the Strava account—may obtain reusable credentials.
The refresh token presents the greater long-term risk because it can be exchanged for new access tokens. The access token immediately permits API access within its granted scope. The documented authorization flow requests
activity:read_all, which may include private activity data.Attack Path
- A user or agent configures valid Strava client credentials and a refresh token.
- The documented command invokes
scripts/refresh_token.sh. - The script sends the credentials to Strava's official OAuth endpoint and receives fresh tokens.
- Lines 27–32 write the complete access and refresh tokens to standard output.
- An agent transcript, CI logger, terminal recorder, process supervisor, or another output-capture mechanism retains the plaintex ...[truncated 1056 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove every statement that prints complete access or refresh tokens.
- Return only a generic success message and non-sensitive expiration information.
- Write refreshed credentials directly to an approved secret manager or a dedicated credential file with restrictive permissions, such as mode
0600. - If automatic credential storage is unavailable, require a secure interactive workflow rather than exposing credentials through normal standard output.
- If partial token identification is operationally necessary, display only a short redacted suffix and never enough token material to permit authentication.
- Ensure CI/CD, agent, and process-supervisor configurations do not capture secret-bearing output.
- Avoid printing the complete OAuth response on failure, because future or unusual responses may contain sensitive fields.
- Revoke and rotate tokens that may already have appeared in logs or transcripts, and remove retained copies from logging systems where feasible.
