T09 · Insecure Skill Coding Practices
- Location
scripts/install.sh:66- Finding
RapidAPI Key Exposed Through Command-Line Arguments and Insecure File Permissions
- Content
View full analysis
/dev/null | cut -d'=' -f2 | tr -d '"') fi if [ -n "$RAPIDAPI_KEY" ]; then if [ -f "$ENV_FILE" ]; then if grep -q "^RAPIDAPI_KEY=" "$ENV_FILE"; then sed -i "s/^RAPIDAPI_KEY=.*/RAPIDAPI_KEY=$RAPIDAPI_KEY/" "$ENV_FILE" else echo "RAPIDAPI_KEY=$RAPIDAPI_KEY" >> "$ENV_FILE" fi else echo "RAPIDAPI_KEY=$RAPIDAPI_KEY" > "$ENV_FILE" fi echo -e "${GREEN}✅ RapidAPI key saved to .env${NC}" ``` The documentation actively recommends passing the credential as a command-line argument: ```bash echo "RAPIDAPI_KEY=your_key_here" > ~/clawd/skills/zillow-airbnb-matcher/.env ``` ```bash bash ~/clawd/skills/zillow-airbnb-matcher/scripts/install.sh --rapidapi-key YOUR_KEY_HERE ``` The runtime setup message provides similar plaintext storage guidance: ```javascript console.log(` echo "RAPIDAPI_KEY=your_key_here" >> ${path.join(__dirname, '../.env')}`); ``` ### Technical Analysis The installer accepts the RapidAPI credential through `--rapidapi-key`. Command-line arguments are not an appropriate secret transport mechanism because the complete invocation may be: - Persisted in the user's shell history. - Recorded by terminal session logging or administrative auditing. - Temporarily visible to local process-monitoring facilities. - Captured in deployment logs, support transcripts, or automation output. The installer ...[truncated 2378 chars]- Remediation
View remediation
"$ENV_FILE" ``` Values should also be safely escaped if arbitrary key formats are supported. 5. **Harden pre-existing files.** Apply `chmod 600 "$ENV_FILE"` even when the file already exists. 6. **Update `GUIDE.md` and runtime setup output.** Remove examples that place real credentials in shell commands. Instruct users to use a secure prompt, protected environment injection, or the platform's secret store. 7. **Add `.env` to `.gitignore`** and document that it must never be committed, copied into support tickets, or included in diagnostic archives. 8. **Rotate potentially exposed keys.** Users who followed the existing command-line instructions should revoke and regenerate their RapidAPI key, especially where shell history or session logs are retained. ]]>
