T09 · Insecure Skill Coding Practices
- Location
scripts/billing.py:51- Finding
SkillPay API Key Exposure Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/billing.py, lines 51–60
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: MediumVulnerable Code
python p = argparse.ArgumentParser() p.add_argument("--user-id", required=True) p.add_argument("--amount", type=float, default=0.001) p.add_argument("--api-key", default=None) g = p.add_mutually_exclusive_group() g.add_argument("--charge", action="store_true", default=True) g.add_argument("--balance", action="store_true") g.add_argument("--payment-link", action="store_true") a = p.parse_args() if a.balance: r = balance(a.user_id, a.api_key)The parsed credential is also passed to the charge or payment-link functions on the subsequent branches:
python elif a.payment_link: r = payment_link(a.user_id, a.amount or 5.0, a.api_key) else: r = charge(a.user_id, a.amount, a.api_key)Technical Analysis
The script allows the SkillPay API credential to be supplied using the
--api-keycommand-line option. Command-line arguments are not an appropriate secret transport mechanism because they can be exposed through:- Process inspection utilities while the command is running.
- Operating-system process accounting or monitoring systems.
- Shell command history.
- Automation logs, diagnostic output, and job-control interfaces.
A local user or monitoring process with permission to inspect the invoking user's processes or command history could recover the credential. The recovered key is transmitted to the declared SkillPay endpoint as an
X-API-Keyheader, so possession of it may enable unauthorized requests to the billing API.Sending the key to
https://skillpay.me/api/v1is consistent with the billing functionality disclosed inSKILL.mdand is not evidence of covert exfiltration. The vulnerability is specifically the optional command-line method used to provide that secret.Attack Pat
...[truncated 1262 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
--api-keycommand-line option and do not accept secrets through process arguments. - Read the credential exclusively from
SKILLPAY_API_KEYor a dedicated secret-management service. - For interactive use, optionally obtain the key through
getpass.getpass()so it is not echoed or retained in shell history. - Ensure application, orchestration, and diagnostic logs redact API keys and authorization headers.
- Grant the key only the minimum billing permissions required by this Skill and use a separate credential for each deployment.
- Rotate any key that has previously been supplied through
--api-key, because it may already exist in process records or shell history. - Apply server-side transaction limits, auditing, anomaly detection, and key revocation controls to reduce the consequences of disclosure.
- Remove the
