T09 · Insecure Skill Coding Practices
- Location
references/godaddy.md:15- Finding
GoDaddy API Credentials Exposed Through Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This domain-management skill is coherent, but it can make high-impact registrar changes and its examples risk exposing registrar credentials.
Install only if you are comfortable giving the agent registrar-level authority. Use sandbox accounts first, avoid pasting production secrets into visible commands, store credentials with restrictive permissions, require explicit confirmation before purchases, renewals, DNS replacements, nameserver changes, unlocks, or transfer-code requests, and rotate any registrar keys that may have appeared in logs or command traces.
references/godaddy.md:15GoDaddy API Credentials Exposed Through Command-Line Arguments
references/name-com.md:10name.com API Token Exposed Through Curl Command-Line Arguments
references/namecheap.md:34Namecheap API Key and Personal Data Exposed in Request URLs
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# name.com (default)
curl -u "$NAMECOM_USERNAME:$NAMECOM_TOKEN" \
"https://api.name.com/v4/domains:checkAvailability" \
-d '{"domainNames":["example.com"]}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# GoDaddy API Reference
Base URL: `https://api.godaddy.com/v1`
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
The authentication example embeds API key and secret usage directly in command lines without an accompanying warning about secret exposure risks in shell history, logs, screenshots, or agent traces. In an agent skill context, this increases the chance that credentials are copied, surfaced to users, or propagated into telemetry.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Auth: `Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET`
Get credentials: developer.godaddy.com → API Keys → Create New Key
- **OTE (test):** `https://api.ote-godaddy.com/v1` (sandbox)
- **Production:** `https://api.godaddy.com/v1`
---
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -H "Authorization: sso-key $GODADDY_API_KEY:$GODADDY_API_SECRET" \
"https://api.godaddy.com/v1/domains/available?domain=example.com"
The purchase example performs a billable, account-affecting action but lacks a prominent warning that it can incur real charges and register a live domain. In a domain-management skill, this omission makes accidental financial and ownership changes more likely during automated or semi-automated use.
No suspicious patterns detected.