T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:20- Finding
API Token Exposed Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
"}' ``` The operation definition declares the token as a query parameter: ```js { "defaultValue": null, "description": "User's authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" } ``` All parameters declared with `location === "query"`, including the token, are appended to the URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The resulting URL is then sent to the fixed HTTPS service: ```js let response; try { response = await fetch(url, requestInit); } catch (error) { fail("Network request failed.", { cause: error instanceof Error ? error.message : String(error), operationId: operation.operationId, }); } ``` ### Technical Analysis Shell expansion of `"$JUST_ONE_API_TOKEN"` makes the actual credential part of the Node process argument vector. Depending on operating-system permissions and runtime environment, command-line arguments can b ...[truncated 2344 chars]- Remediation
View remediation
