T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:19- Finding
API Credential Exposed Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` All parameters designated as query parameters, including the token, are appended to the request URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The documentation additionally directs users to supply the token as a command-line argument: ```bash node {baseDir}/bin/run.mjs --operation "htmlV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"url":""}' ``` ### Technical Analysis The Skill requires an API token for its declared operation, so transmitting an authentication credential to JustOneAPI is functionally necessary. However, placing the credential in the URL query string exceeds the minimum exposure necessary for authentication. After `injectToken` assigns the command-line token to `params.token`, `applyQue ...[truncated 2552 chars]- Remediation
View remediation
