T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:226- Finding
API Token Exposed Through Process Arguments and URL Query Parameters
- Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` All query parameters, including the token, are added to the URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.sea ...[truncated 2399 chars]- Remediation
View remediation
`, if supported by JustOneAPI. 3. If the external API contract strictly requires a query token: - Avoid logging the complete request URL. - Configure gateways, proxies, monitoring systems, and error handlers to redact the `token` parameter. - Use short-lived, narrowly scoped tokens. - Rotate the token immediately after suspected exposure. 4. Reject `token` inside `--params-json` so callers cannot bypass the safer credential source. 5. Update `SKILL.md` to instruct users to set `JUST_ONE_API_TOKEN` without expanding it into the command line. 6. Ensure backend errors and diagnostics never include the complete request URL or authentication value. ]]>
