T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:22- Finding
API Credential Exposed Through URL Query Parameters and Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
bin/run.mjs:22-31,bin/run.mjs:79-85,bin/run.mjs:99,bin/run.mjs:168-180,bin/run.mjs:223-233; documented invocation atSKILL.md:40
Vulnerability Type: Sensitive credential exposure
Risk Level: MediumVulnerable Code
js { "defaultValue": null, "description": "Access token for the API service.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" }js const params = parseParams(args.paramsJson); applyDefaults(operation, params); injectToken(operation, params, args.token); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url);js response = await fetch(url, requestInit);js function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; }js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } }The documented invocation also supplies the secret through a command-line argument:
bash node {baseDir}/bin/run.mjs --operation "searchReelsV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"keyword":"<keyword>"}'Technical Analysis
The operation manifest classifies the AP ...[truncated 2752 chars]
- Remediation
View remediation
Remediation Suggestions
-
Change the API authentication scheme to use an HTTP authorization header, such as:
js const requestInit = { headers: { "accept": "application/json", "authorization": `Bearer ${token}`, }, method: operation.method, }; -
Remove
tokenfrom the operation’s query-parameter list so thatapplyQueryParamscannot append it to the URL. -
Read the credential directly from
process.env.JUST_ONE_API_TOKENrather than requiring it through--token. If CLI compatibility must be retained, prefer the environment variable and clearly deprecate the command-line option. -
Never include the token or complete authenticated URL in normal output, errors, debug logs, telemetry, or exception metadata.
-
Disable automatic cross-origin redirects for authenticated requests, or explicitly verify that every redirect remains on the expected HTTPS origin before forwarding credentials.
-
Configure API gateways, proxies, and server access logs to redact existing
tokenquery parameters while migration is in progress. -
Rotate credentials that may previously have appeared in process metadata or URL logs, and apply minimum API scopes, short expiration periods, quotas, and provider-side restrictions where supported.
-
Update
SKILL.md,generated/operations.json, andgenerated/operations.mdto describe the safer authentication mechanism consistently.
-
