T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:19- Finding
API Token Exposed Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
bin/run.mjs:19-24, 138-158, 207-217, 243-255, 288-310;SKILL.md:49, 57
Vulnerability Type: API credential exposure
Risk Level: MediumThe API token is accepted through the
--tokencommand-line argument and subsequently inserted into the request URL as a query parameter.Vulnerable Code
bin/run.mjs:19-24defines the credential as a query parameter:js { "defaultValue": null, "description": "API access token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" },bin/run.mjs:138-158constructs the URL, adds all query parameters, and sends it:js const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, }; if (operation.requestBody && params.body !== undefined) { requestInit.body = JSON.stringify(params.body); requestInit.headers["content-type"] = operation.requestBody.contentType || "application/json"; } let response; try { response = await fetch(url, requestInit);bin/run.mjs:207-217reads the token from the command line:js if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } fail(`Unknown argument "${flag}".`);bin/run.mjs:243-255places that token into the parameter collection:js function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.toke ...[truncated 4141 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove command-line token handling. Read the token directly from
process.env.JUST_ONE_API_TOKENso it is not included in the process argument vector:js const token = process.env.JUST_ONE_API_TOKEN; if (!token) { fail("JUST_ONE_API_TOKEN is required.", { operationId: operation.operationId, }); } -
Use an authorization header if the upstream API supports it. Remove
tokenfrom query-parameter serialization and send it through a dedicated header:js const requestInit = { headers: { accept: "application/json", authorization: `Bearer ${token}`, }, method: operation.method, }; -
If query authentication is an unavoidable upstream requirement:
- Continue reading the token from the environment rather than
--token. - Build redacted URL representations for logging and diagnostics.
- Never include the complete request URL in errors, traces, or telemetry.
- Configure gateways, proxies, and server access logs to redact the
tokenparameter. - Document that query-string authentication remains a residual exposure risk.
- Use short-lived, narrowly scoped tokens where supported.
- Continue reading the token from the environment rather than
-
Prevent accidental alternate injection. Reject
tokeninside--params-jsonrather than allowing it to bypass the intended credential source. -
Update documentation. Replace the command in
SKILL.mdwith one that relies on the inherited environment variable and does not include--token. -
Rotate exposed credentials. After deploying the safer authentication flow, revoke and replace tokens previously used with the command-line/query-string implementation.
-
