T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:518- Finding
API Token Exposed Through Process Arguments and URL Query Parameters
- Content
View full analysis
" --token "$JUST_ONE_API_TOKEN" --params-json '{"key":"value"}' ``` `bin/run.mjs:472-490`: ```javascript function parseArgs(argv) { const parsed = { operation: null, paramsJson: "{}", token: null }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } ``` `bin/run.mjs:518-528`: ```javascript function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` `bin/run.mjs:558-566`: ```javascript function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` `bin/run.mjs:431`: ```javascript response = await fetch(url, requestInit); ``` ### Technical Analysis The documented invocation expands `JUST_ONE_API_TOKEN` into the `--token` command-line argument. Depending on the ...[truncated 2735 chars]- Remediation
View remediation
" \ --params-json '{"key":"value"}' ``` The environment should preferably be provisioned by the execution environment rather than repeated inline. 2. **Use header-based authentication where supported** - Prefer an HTTP authorization header, such as: ```javascript const token = process.env.JUST_ONE_API_TOKEN; requestInit.headers.authorization = `Bearer ${token}`; ``` - Confirm the exact header and authentication scheme with JustOneAPI documentation before changing the client. 3. **Harden unavoidable query-parameter authentication** - If the service only supports a `token` query parameter, configure clients, gateways, proxies, application logs, tracing systems, and server access logs to redact it. - Never include the complete request URL in errors or diagnostics. - Disable URL capture in telemetry where redaction cannot be guaranteed. 4. **Validate credential presence securely** - Fail with a generic message if the environment variable is absent. - Do not print the token or the constructed authenticated URL to standard output or standard error. 5. **Reduce credential impact** - Use narrowly scoped tokens where supported. - Apply usage limits, expiration, rotation, and anomaly monitoring. - Revoke and replace any token suspected of appearing in process telemetry or URL logs. ]]>
