T09 · Insecure Skill Coding Practices
- Location
SKILL.md:137- Finding
Cloud Provider Token Exposed Through Process Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 137 and 173
Vulnerability Type: Secret exposure through command-line arguments
Risk Level: MediumVulnerable Code
The same insecure alternative appears at both locations:
sh # or: devopsellence provider login hetzner --token "$HCLOUD_TOKEN"Technical Analysis
The instruction expands
HCLOUD_TOKENinto the command's argument vector. Depending on the operating system and execution environment, command arguments may be visible to other local processes, process-monitoring tools, audit systems, shell tracing, diagnostic collectors, or CI/CD telemetry.Although the Skill presents an stdin-based command as the preferred option, explicitly documenting the
--tokenalternative can cause agents or users to select the less secure path. The environment variable itself is not hardcoded, but its value becomes plaintext in the spawned process's arguments.Attack Path
- A user stores a valid Hetzner provider token in
HCLOUD_TOKEN. - The user or agent follows the documented
--tokenalternative. - The shell expands the variable and places its plaintext value in the
devopsellenceprocess argument vector. - A local process with sufficient process-inspection access, an audit service, or a telemetry collector captures the arguments while the command runs.
- The observer extracts the token and submits authenticated requests to the provider API.
- The attacker performs actions allowed by the token's assigned provider permissions.
This path requires local process-observation capability or access to tooling that records command arguments.
Impact Assessment
A disclosed token may permit unauthorized access to the associated Hetzner account or project. The exact impact depends on the token's provider-side permissions and may include viewing infrastructure, provisioning or modifying servers, disrupting workloads, deleting resources, or incurring costs.
The issue does not it ...[truncated 136 chars]
- A user stores a valid Hetzner provider token in
- Remediation
View remediation
Remediation Suggestions
- Remove both documented
--token "$HCLOUD_TOKEN"alternatives. - Retain only the stdin-based form:
sh printf '%s' "$HCLOUD_TOKEN" | devopsellence provider login hetzner --stdin- Add an explicit instruction prohibiting provider secrets in command-line arguments.
- Recommend disabling shell tracing before handling secrets and ensuring command output does not echo credential material.
- Encourage narrowly scoped, short-lived provider tokens where supported, with prompt rotation after suspected exposure.
- If the CLI supports secure credential helpers or platform secret stores, prefer those mechanisms over persistent plaintext environment variables.
- Remove both documented
