T09 · Insecure Skill Coding Practices
- Location
illustration.md:55- Finding
API Credentials Exposed Through Shell Output and Process Arguments
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 fi ``` 2. Apply the same presence-only check to `GEMINI_API_KEY`. 3. Avoid placing secrets in URLs or command-line arguments. Prefer an SDK or an authentication header where the provider supports it. 4. Disable shell tracing before handling credentials and redact authorization headers and sensitive query parameters from logs. 5. Run API clients in an environment where unrelated users and processes cannot inspect process metadata. 6. Rotate any keys that may already have appeared in tool transcripts or logs. 7. Use narrowly scoped credentials with spending limits, quotas, expiration, and provider-side monitoring. ]]>
