T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:24- Finding
API Token Exposed Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:39-44;bin/run.mjs:24-31, 65-71, 196-206
Vulnerability Type: API credential exposure through process arguments and URL query parameters
Risk Level: MediumVulnerable Code
SKILL.md:39-44:bash node {baseDir}/bin/run.mjs --operation "getInstagramUserDetailV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"username":"<username>"}'markdown - Required: `JUST_ONE_API_TOKEN` - Pass the token with `--token "$JUST_ONE_API_TOKEN"`; do not paste token values into chat messages, screenshots, or logs.bin/run.mjs:24-31:javascript { "defaultValue": null, "description": "Access token for the API service.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" }bin/run.mjs:65-71:javascript const params = parseParams(args.paramsJson); applyDefaults(operation, params); injectToken(operation, params, args.token); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url);bin/run.mjs:196-206:javascript function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } }Technical Analysis
The documented invocation passes
JUST_ONE_API_TOKENthrough the--tokencommand-line option. Command-line arguments can be exposed to local process-inspection facilities, execution telemetry, shell tracing, diagnostic tooling, and CI/CD logs.The helper subsequently injects the token into the parameters and serializes all query-located parameters into the request URL. The resulting request therefore includes the credent ...[truncated 1978 chars]
- Remediation
View remediation
Remediation Suggestions
- Read the token directly from
process.env.JUST_ONE_API_TOKENrather than requiring it as a command-line argument. - Remove or deprecate
--tokento prevent credentials from appearing in process listings and command logs. - Send the credential in an
Authorizationheader if JustOneAPI supports header-based authentication:
javascript const token = process.env.JUST_ONE_API_TOKEN; if (!token) { fail("JUST_ONE_API_TOKEN is required."); } const requestInit = { method: operation.method, headers: { accept: "application/json", authorization: `Bearer ${token}`, }, };- Remove
tokenfrom query-parameter serialization when header authentication is available. - Reject
tokeninside--params-jsonso credentials have one controlled input path. - If the upstream service only supports query authentication, document the residual exposure and configure clients, proxies, gateways, servers, monitoring systems, and error reporters to redact the
tokenquery parameter. - Ensure error messages never include the complete request URL or credential.
- Rotate any token suspected of having appeared in process telemetry, shell history, CI logs, proxy logs, or server access logs.
- Read the token directly from
