T09 · Insecure Skill Coding Practices
- Location
SKILL.md:22- Finding
API token exposure through command-line arguments and cron configuration
- Content
View full analysis
--count 5 ``` ## Usage ### Generate a quiz manually ```bash python3 scripts/quiz_generator.py --token --count 5 ``` ### Delete a mastered word ```bash python3 scripts/vocab_manager.py --token --action delete --word-id ``` ### List all words ```bash python3 scripts/vocab_manager.py --token --action list ``` ``` The corresponding scripts accept credentials from command-line arguments: ```python parser.add_argument( "--token", help="API Token; if omitted, read from the EUDIC_TOKEN environment variable" ) args = parser.parse_args() token = args.token or os.environ.get("EUDIC_TOKEN") if not token: print("Error: provide --token or set EUDIC_TOKEN") sys.exit(1) ``` ### Technical Analysis Command-line arguments are not an appropriate channel for long-lived credentials. Depending on the operating system and local security configuration, command arguments may be exposed through: - Process inspection interfaces such as `ps` or `/proc//cmdline`. - Shell history files. - Process monitoring and auditing services. - Scheduler logs and diagnostic output. - Persistent crontab entries readable by administrators or other privileged services. The documented cron command is particularly problematic because it directs the user to store the Eudic API token in persistent scheduler configuration. This exceeds the minimum necessary exposure because all three scripts al ...[truncated 1401 chars]- Remediation
View remediation
