T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:204- Finding
API Token Exposed Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:41,50;bin/run.mjs:24-31,81-85,204-212,226-235
Vulnerability Type: Credential exposure through process arguments and URL query strings
Risk Level: MediumThe documented invocation passes the API token as a command-line argument:
bash node {baseDir}/bin/run.mjs --operation "communityListV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"cityId":"<cityId>"}'The executable defines the token as a required query parameter:
js { "defaultValue": null, "description": "User authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" }It then injects the command-line token into the request parameters:
js function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; }Every parameter marked as a query parameter, including
token, is appended to the URL:js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } }Technical Analysis
Authentication tokens are sensitive credentials and should not be placed in process command lines or URL query strings.
Passing the token with
--tokenmay expose it through process listings, process-monitoring software, shell history when literal values are used, job-control metadata, diagnostic tooling, or command exec ...[truncated 2225 chars]- Remediation
View remediation
Remediation Suggestions
- Read the token directly from
process.env.JUST_ONE_API_TOKENinstead of accepting it through--token. - Remove or deprecate the command-line token option so the secret is not present in the process argument vector.
- If the upstream API supports it, send the credential in an authorization header, such as:
js const token = process.env.JUST_ONE_API_TOKEN; requestInit.headers.authorization = `Bearer ${token}`; - Remove
tokenfrom the operation's query-parameter definition and reject atokenproperty supplied through--params-json. - If the upstream service mandates query-based authentication, request support for header-based authentication. Until then, configure API gateways, proxies, tracing systems, and server logs to redact the
tokenparameter. - Avoid logging complete request URLs, request options, process arguments, or error objects that might contain credentials.
- Use short-lived, narrowly scoped tokens with rotation, revocation, quota limits, and endpoint restrictions.
- Update
SKILL.mdso examples rely on the environment variable internally rather than forwarding its value through a command-line option.
- Read the token directly from
