T09 · Insecure Skill Coding Practices
- Location
scripts/sentiment.py:1694- Finding
Credentials are exposed through command-line arguments, plaintext configuration, process arguments, and command output
- Content
View full analysis
dict: if CONFIG_PATH.exists(): try: return json.loads(CONFIG_PATH.read_text(encoding="utf-8")) except Exception: pass return {"tier": "FREE", "glm_api_key": "", "feishu_webhook": "", "smtp_config": {}} def save_config(cfg: dict): CONFIG_PATH.write_text( json.dumps(cfg, ensure_ascii=False, indent=2), encoding="utf-8", ) ``` The API key is also passed to an external process as a command-line argument: ```python result = subprocess.run( ["curl", "-s", "-X", "POST", GLM_API_URL, "-H", f"Authorization: Bearer {api_key}", "-H", "Content-Type: application/json", "-d", json.dumps(payload, ensure_ascii=False)], capture_output=True, text=True, timeout=30 ) ``` The CLI exposes arbitrary configuration values, including secrets: ```python elif cmd == "config-get": key = sys.argv[2] if len(sys.argv) > 2 else "" val = get_config(key) print(json.dumps({"ok": True, "key": key, "value": val}, ensure_ascii=False)) elif cmd == "config-set": # python3 sentiment.py config-set key = sys.argv[2] if len(sys.argv) > 2 else "" value = sys.argv[3] if len(sys.argv) > 3 else "" # Try to parse JSON try: value = json.loads(value) except Exception: pass set_config(key, value) print(json.dumps({"ok": True, "key": key, "value": value}, ensure_ascii=False)) ``` The documented setup also places secrets directly in shell command arguments: ```bash python3 scripts/sentiment.py config-set glm_api_key "your_key" python3 scripts/sentiment.py config-set feishu_webhook "https://open.feishu.cn/..." python3 scripts/sentiment.py config-se ...[truncated 2112 chars]- Remediation
View remediation
