T09 · Insecure Skill Coding Practices
- Location
scripts/kubera.py:19- Finding
API Credentials Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/kubera.py:19-20andscripts/kubera.py:206-207
Vulnerability Type: Command-line credential exposure
Risk Level: MediumVulnerable Code
python def get_config(args): api_key = getattr(args, 'api_key', None) or os.environ.get('KUBERA_API_KEY') secret = getattr(args, 'secret', None) or os.environ.get('KUBERA_SECRET') if not api_key or not secret: print("Error: Set KUBERA_API_KEY and KUBERA_SECRET env vars, or use --api-key/--secret", file=sys.stderr) sys.exit(1) return api_key, secretpython parser.add_argument('--api-key', help='Kubera API key') parser.add_argument('--secret', help='Kubera API secret')Technical Analysis
The program permits users to provide the Kubera API key and API secret directly through
--api-keyand--secret. Command-line arguments are not an appropriate secret transport mechanism because they can be recorded in shell history and may be exposed through operating-system process inspection facilities while the program is running.Possession of both credentials enables an attacker to construct valid HMAC-SHA256 signatures for Kubera API requests. Although the API secret is not transmitted to Kubera, exposing it locally alongside the API key defeats the authentication scheme.
The environment-variable configuration described in
SKILL.mdis safer than command-line arguments, but the insecure command-line alternative remains explicitly supported and encouraged by the program's error message.Attack Path
- A user invokes the program with credentials on the command line, for example:
bash python3 scripts/kubera.py --api-key API_KEY --secret API_SECRET summary - The command and credentials are retained in shell history or temporarily exposed through process argument inspection.
- A local attacker or another process with sufficient process-inspe ...[truncated 1096 chars]
- A user invokes the program with credentials on the command line, for example:
- Remediation
View remediation
Remediation Suggestions
- Remove the
--api-keyand--secretcommand-line options so credentials cannot be supplied through process arguments. - Obtain credentials from protected environment variables, an operating-system credential manager, or a configuration file restricted to the owning user.
- If interactive credential entry is needed, use Python's
getpass.getpass()for the secret so it is not echoed or stored in shell history. - Update the error message, module documentation, and usage instructions to stop recommending credential-bearing command-line options.
- Continue recommending read-only API credentials by default and require users to create a separate, narrowly scoped write-enabled key only when update functionality is necessary.
- Advise users who previously supplied credentials through command-line arguments to clear affected shell history securely and rotate the exposed API key and secret.
- Avoid logging authentication headers, signatures, command namespaces, or configuration objects that may contain credentials.
- Remove the
