T09 · Insecure Skill Coding Practices
- Location
src/garmer/cli.py:73- Finding
Garmin Password Can Be Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
src/garmer/cli.py:73-79,src/garmer/cli.py:905
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: MediumVulnerable Code
python def cmd_login(args: argparse.Namespace) -> int: """Handle login command.""" email = args.email or input("Garmin Connect email: ") password = args.password or getpass.getpass("Garmin Connect password: ") try: client = GarminClient.from_credentials( email=email, password=password, save_tokens=True, )python login_parser.add_argument("-p", "--password", help="Garmin Connect password")Technical Analysis
The interactive login path correctly uses
getpass.getpass(), which avoids echoing the password. However, the CLI also permits the password to be supplied through-por--password.Command-line arguments are commonly exposed through:
- Shell history files
- Process inspection utilities such as
ps /proc/<pid>/cmdlineon Linux- Terminal session recording
- CI/CD logs and automation telemetry
- Process monitoring and endpoint security products
The password is legitimately transmitted to Garmin through the
garthauthentication library, and no evidence indicates transmission to an unrelated destination. The vulnerability is the local exposure created before authentication occurs.Attack Path
- A user runs a command such as
garmer login --email user@example.com --password SECRET. - The shell records the full command in its history, or the operating system exposes it in the process argument list.
- Another local account, monitoring process, or log collector reads the exposed argument.
- The attacker uses the recovered password to authenticate to the victim's Garmin account.
- The attacker may access sensitive profile, activity, location-related, sleep, heart ...[truncated 582 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
-pand--passwordcommand-line options. - Require hidden interactive entry through
getpass.getpass()for normal CLI use. - If non-interactive authentication is essential, accept credentials through a protected credential provider or operating-system keyring rather than process arguments.
- If stdin must be supported, require an explicit option such as
--password-stdin, document its risks, and ensure the value is never logged. - Add automated tests confirming that credential values do not appear in command output, error messages, or logs.
- Recommend password rotation to users who have previously supplied passwords through the command line.
- Remove the
