T09 · Insecure Skill Coding Practices
- Location
scripts/cmaiot.js:8- Finding
Product Access Key Exposed Through Command-Line Arguments and Plaintext Storage
- Content
View full analysis
p.productId === productId).accessKey; } function addProduct(productId, accessKey) { if (!productId || !accessKey) { showHelp(); return false; } const exist = config.products.find(p => p.productId === productId); if (exist) { return false; } config.products.push({ productId, accessKey }); fs.writeFileSync(config_file, JSON.stringify(config, null, 2)); return true; } ``` `scripts/cmaiot.js:119-131`: ```javascript async function main() { const cmd = process.argv[2]; const target = process.argv[3]; const jsonString = process.argv[4]; if (!cmd) { showHelp(); return; } config = readConfig(); ``` ### Technical Analysis The documented credential-enrollment interface requires users to place the product ID and access key directly in a command-line argument. Command-line secrets may be retained in shell history and can be exposed through process-inspection facilities to users or processes with sufficient local visibility. After parsing the argument, the script stores the access key unencrypted in `scripts/config.json`. The call to `fs.writeFileSync` does not specify a restrictive file mode. Consequently, effective permissions depend on the current process umask an ...[truncated 2573 chars]- Remediation
View remediation
