T09 · Insecure Skill Coding Practices
- Location
SKILL.md:92- Finding
WordPress Application Password Exposed Through Process Arguments
- Content
View full analysis
" --fields password --reveal) WP_BASE="https:///wp-json/wp/v2" # Verify auth works before proceeding curl -s -u "$WP_USER:$WP_PASS" "$WP_BASE/users/me" | jq '{id, name}' # List posts curl -s -u "$WP_USER:$WP_PASS" "$WP_BASE/posts?per_page=20&status=any" | jq '[.[] | {id, title: .title.rendered, status}]' # Get post content (raw blocks) curl -s -u "$WP_USER:$WP_PASS" "$WP_BASE/posts/?context=edit" | jq -r '.content.raw' # Create post (draft) curl -s -X POST -u "$WP_USER:$WP_PASS" "$WP_BASE/posts" \ -H "Content-Type: application/json" \ -d '{"title":"Post Title","content":"Body
","status":"draft"}' # Update post content curl -s -X POST -u "$WP_USER:$WP_PASS" "$WP_BASE/posts/" \ -H "Content-Type: application/json" \ -d "{\"content\": $(cat /tmp/content.html | python3 -c 'import json,sys; print(json.dumps(sys.stdin.read()))')}" # Publish curl -s -X POST -u "$WP_USER:$WP_PASS" "$WP_BASE/posts/" \ -H "Content-Type: application/json" \ -d '{"status": "publish"}' ``` ### Technical Analysis The application password is retrieved in plaintext from 1Password and stored in the `WP_PASS` shell variable. Expanding that variable inside curl's `-u` argument places the username and plaintext password in curl's process argument vector. Depending on the operating system, process-monitoring configuration, and timing, command arguments may be visible to other local users, diagnostic tools, audit systems, process supervisors, or logs. Keeping the password only in a shell variable does not prevent this exposure once it is expanded into a command-line argument. The SSH and SSH-agent access documented by the Skill are consistent with its declared WordPress administration function and do no ...[truncated 1903 chars]- Remediation
View remediation
