T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:136- Finding
Passwords Exposed Through Command-Line Arguments
- Content
View full analysis
" ``` ```bash cmd_entropy() { local pw="${1:-}" [[ -z "$pw" ]] && die "Usage: password entropy " ``` ```bash cmd_check_leak() { local pw="${1:-}" [[ -z "$pw" ]] && die "Usage: password check-leak " ``` ```bash case "$cmd" in generate) cmd_generate "$@" ;; strength) cmd_strength "$@" ;; entropy) cmd_entropy "$@" ;; batch) cmd_batch "$@" ;; check-leak) cmd_check_leak "$@" ;; ``` ### Technical Analysis The `strength`, `entropy`, and `check-leak` operations receive passwords as positional command-line arguments. Command-line arguments are not an appropriate transport mechanism for secrets because they may be: - Recorded in interactive shell history. - Exposed through process inspection facilities while the command is running. - Captured by process accounting, diagnostic tools, audit systems, wrappers, or terminal logging. - Retained in automation logs when the command is executed by another program. Although the breach-checking implementation sends only the first five characters of a SHA-1 hash to the Have I Been Pwned API, that privacy measure does not protect the password before it reaches the script. The local command invocation still exposes the original plaintext password. ### Attack Path 1. A user invokes a command such as: ```bash scripts/script.sh check-leak 'SecretPassword123!' ``` 2. The plaintext password becomes part of the process argument vector and may also be written to the user's shell-history file. 3. A local user or monitoring process wit ...[truncated 719 chars]- Remediation
View remediation
&2 ``` - Support standard input for non-interactive use, with documentation warning users to avoid plaintext command-line arguments. - Prefer reading from `/dev/tty` for interactive prompts so redirected output does not expose the password. - Clear the variable after use where practical: ```bash unset pw ``` - Update `SKILL.md` and command usage messages so examples never place passwords directly on the command line. - If backward compatibility requires positional arguments temporarily, emit a prominent warning and deprecate that interface. ]]>
