T09 · Insecure Skill Coding Practices
- Location
scripts/moji_manager.py:186- Finding
Session Token Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/moji_manager.py:186,196; also present inscripts/moji_quiz.py:150,154
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: MediumEvidence
scripts/moji_manager.py:186,196:python parser.add_argument("--token", help="sessionToken, or set the MOJI_TOKEN environment variable") token = args.token or os.environ.get("MOJI_TOKEN")scripts/moji_quiz.py:150,154:python parser.add_argument("--token", help="sessionToken, or set the MOJI_TOKEN environment variable") token = args.token or os.environ.get("MOJI_TOKEN")Technical Analysis
Both command-line interfaces permit the MojiDict session token to be supplied with
--token. Command-line arguments may be exposed through shell history, process inspection facilities, job-control systems, diagnostic reports, CI/CD logs, or command auditing.The token is subsequently used as an authenticated MojiDict credential. In
scripts/moji_manager.py, it is transmitted as_SessionToken,x-moji-session-id, andx-moji-token. Accepting the token through process arguments is not necessary because the scripts already support theMOJI_TOKENenvironment variable.No evidence indicates that the token is sent to an unrelated domain. The network transmission itself is directed to the declared MojiDict HTTPS API and is necessary for authenticated functionality. The vulnerability is the avoidable local disclosure channel created by the command-line option.
Attack Path
- A user starts either script with a command such as
python3 scripts/moji_manager.py --token SECRET --device-id DEVICE --action stats. - The complete command is recorded in shell history, process telemetry, an automation log, or another process-accessible command-line interface.
- A local user, administrator, monitoring service, or party with access to those logs retrieves the token.
- T ...[truncated 691 chars]
- A user starts either script with a command such as
- Remediation
View remediation
Remediation Suggestions
- Remove the
--tokenoption from both scripts. - Retrieve the token from a protected credential store, a narrowly scoped environment variable, or an interactive hidden prompt implemented with
getpass.getpass(). - If command-line support must remain for compatibility, display a prominent warning and require explicit opt-in before accepting a token this way.
- Ensure application and CI logs redact values associated with
MOJI_TOKEN,_SessionToken,x-moji-session-id, andx-moji-token. - Avoid printing request headers, payloads, or exception objects that might later include authentication data.
- Document token revocation and rotation procedures for users who may previously have supplied credentials through command-line arguments.
- Remove the
