T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:29- Finding
API Credential Exposed Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
bin/run.mjs:29-37, 78-89, 180-222; related usage guidance inSKILL.md:38-45
Vulnerability Type: Sensitive credential exposure
Risk Level: MediumVulnerable Code
The API manifest defines the access token as a query parameter:
js { "defaultValue": null, "description": "Access token for the API service.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" },The token is accepted from a command-line argument, inserted into the parameter object, appended to the request URL, and transmitted:
js const params = parseParams(args.paramsJson); applyDefaults(operation, params); injectToken(operation, params, args.token); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, };js function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } function validateRequired(operation, params) { const missing = []; for (const parameter of operation.parameters) { if (parameter.required && params[parameter.name] === undefined) { missing.push(parameter.name); } } if (operation.requestBody?.required && params.body === undefined) { missing.push("body"); } if (missing.length) { ...[truncated 3898 chars]- Remediation
View remediation
Remediation Suggestions
- Read the credential directly from
process.env.JUST_ONE_API_TOKENrather than accepting it through--token. - Transmit the token in the API's supported authentication header, preferably:
js const token = process.env.JUST_ONE_API_TOKEN; if (!token) { fail("JUST_ONE_API_TOKEN is required."); } const requestInit = { method: operation.method, headers: { accept: "application/json", authorization: `Bearer ${token}`, }, }; - Remove
tokenfrom the operation's query-parameter definition and rejecttokenwhen supplied through--params-json. - If the upstream API supports only query-string authentication, request header-based authentication support from the provider. Until then, explicitly document the residual logging risk and configure all clients, proxies, gateways, and servers to redact the
tokenparameter. - Ensure diagnostic and error handling never prints request URLs, headers, environment values, or parameter objects containing credentials.
- Update
SKILL.md,generated/operations.json, andgenerated/operations.mdso their authentication instructions match the hardened implementation. - Rotate tokens that may already have appeared in process captures, request logs, or observability systems, and restrict token permissions and lifetime where supported.
- Read the credential directly from
