T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:23- Finding
API Token Exposed Through Process Arguments and URL Query Parameters
- Content
View full analysis
item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The resulting URL, containing the plaintext token in its query string, is then supplied to `fetch`: ```javascript const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, }; response = await fetch(url, requestInit); ``` HTTPS protects the request while it is in transit, but it does not prevent credential exposure through local process inspection or URL logging. Command-line arguments may be visible to other authorized local users, process-monitoring agents, crash diagnostics, shell history, or orchestration telemetry. Query strings may be retained by reverse proxies, API gateways, access logs, tr ...[truncated 2326 chars]- Remediation
View remediation
"}' ``` 6. Rotate any token suspected of having appeared in process telemetry, command history, access logs, traces, or diagnostic output. 7. Add automated tests verifying that tokens never appear in generated URLs, standard output, standard error, or error objects. ]]>
