T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:20- Finding
API Authentication Token Exposed in URL Query Parameter
- Content
View full analysis
Vulnerability Details
File Location:
bin/run.mjs, lines 20–28, 89–101, and 231–241
Vulnerability Type: Sensitive credential transmitted in a URL query parameter
Risk Level: MediumVulnerable Code
js { "defaultValue": null, "description": "User's authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" }js const params = parseParams(args.paramsJson); applyDefaults(operation, params); injectToken(operation, params, args.token); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url);js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } }The same query-based authentication scheme is documented in
generated/operations.json, lines 16–24, andgenerated/operations.md, line 16.Technical Analysis
The Skill receives the user's JustOneAPI authentication token and inserts it into
params.token. Because the operation manifest definestokenas a query parameter,applyQueryParams()appends the credential to the request URL. The resulting request has the form:text https://api.justoneapi.com/api/imdb/title-contribution-questions/v1?token=<secret>&id=<title-id>&languageCountry=<locale>HTTPS encrypts the URL while it is in transit, but it does not prevent the complete URL from being recorded at endpoints or inside trusted infrastructure. Query strings are commonly captured by reverse-proxy access logs, API gateway logs, observability platforms, debugging tools, error reports, and monitoring systems. This unnecessarily expa ...[truncated 1671 chars]
- Remediation
View remediation
Remediation Suggestions
-
Use an authentication header supported by the provider, preferably:
js const requestInit = { headers: { accept: "application/json", authorization: `Bearer ${args.token}`, }, method: operation.method, };If JustOneAPI uses a dedicated API-key header, use that header instead of
Authorization. -
Remove
tokenfrom the operation's query-parameter definitions in:bin/run.mjsgenerated/operations.jsongenerated/operations.md
-
Keep credentials separate from general request parameters. Explicitly reject
token,authorization, and other credential-like fields supplied through--params-jsonso they cannot be accidentally serialized into a URL. -
Ensure request diagnostics, telemetry, and error handling redact authorization headers and sensitive query parameters. Never print the token or a complete credential-bearing URL.
-
If the upstream API only supports query-based authentication:
- Document the residual credential-exposure risk.
- Configure all clients, proxies, gateways, servers, and monitoring systems to redact the
tokenparameter. - Apply short token lifetimes, least-privilege scopes, rotation, revocation, and usage alerts.
- Avoid retries or exception messages that could reproduce the request URL.
-
