T09 · Insecure Skill Coding Practices
- Location
parcel-api.js:152- Finding
Missing CLI Options Are Silently Replaced with the Command Name
- Content
View full analysis
Vulnerability Details
File Location:
parcel-api.js, lines 152–160
Vulnerability Type: Improper CLI argument validation
Risk Level: LowVulnerable Code
js const tracking = args[args.indexOf('--tracking') + 1]; const carrier = args[args.indexOf('--carrier') + 1]; const description = args[args.indexOf('--description') + 1]; const notify = args.includes('--notify') ? 'true' : 'false'; if (!tracking || !carrier || !description) { console.error("Usage: parcel-api add --tracking <num> --carrier <code> --description <desc> [--notify]"); process.exit(1); }Technical Analysis
The parser does not verify that each required option exists before reading the following array element. If
args.indexOf()cannot find an option, it returns-1. Adding one results in index0, which contains the command name,"add".Consequently, an omitted
--tracking,--carrier, or--descriptionoption may be assigned"add"instead of an absent value. Because"add"is truthy, the required-argument check does not reliably reject the malformed invocation. The resulting values are passed toaddDelivery()and submitted to the authenticated Parcel API.This is an input-validation and remote-data-integrity flaw. It does not provide command execution, privilege escalation, credential disclosure, or access beyond the privileges already associated with
PARCEL_API_KEY.Attack Path
- A user, automation process, or AI agent invokes the
addcommand while omitting one or more required flags. - For every omitted flag,
indexOf()returns-1. - The expression
-1 + 1selectsargs[0], whose value is"add". - The truthiness validation accepts the substituted value.
addDelivery()sends the malformed delivery record tohttps://api.parcel.app/external/add-delivery/using the configured API key.- If the remote API accepts the malformed fields, unintended data is added to the use ...[truncated 369 chars]
- A user, automation process, or AI agent invokes the
- Remediation
View remediation
Remediation Suggestions
Replace the index arithmetic with parsing that explicitly verifies each option and its value. Prefer a maintained CLI parsing library, or implement a helper that rejects missing flags, missing values, duplicated options, and values that are themselves option tokens.
Validate all inputs before sending the request:
- Require non-empty tracking, carrier, and description values.
- Reject a required option when its next token is absent or starts with
--. - Validate the carrier against the supported-carrier list.
- Enforce reasonable length and character constraints for tracking numbers and descriptions.
- Restrict list mode to the documented
activeandrecentvalues. - Return a nonzero exit status without making an API request when validation fails.
Example hardened parsing:
js function requiredOption(args, name) { const index = args.indexOf(name); if ( index === -1 || index + 1 >= args.length || args[index + 1].startsWith('--') ) { throw new Error(`Missing required option: ${name}`); } return args[index + 1]; } try { const tracking = requiredOption(args, '--tracking'); const carrier = requiredOption(args, '--carrier'); const description = requiredOption(args, '--description'); const notify = args.includes('--notify'); await addDelivery(tracking, carrier, description, notify); } catch (err) { console.error(err.message); process.exit(1); }The
addDelivery()function should then accept a Boolean directly and assignsend_push_confirmation: notify.
