T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:72- Finding
API Token Exposed Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` ```js const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); ``` ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The documented invocation also passes the credential as a command-line argument: ```bash node {baseDir}/bin/run.mjs --operation "getUserProfileV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"userId":""}' ``` ### Technical Analysis The helper places the JustOneAPI access token in two potentially observable locations: 1. The `--token` command-line argument may be visible through local process inspection, diagnostic tooling, shell tracing, process accounting, job runners, or command logging. 2. Be ...[truncated 2208 chars]- Remediation
View remediation
