T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:597- Finding
API Token Exposure Through Process Arguments and URL Query Parameters
- Content
View full analysis
" --token "$JUST_ONE_API_TOKEN" --params-json '{"key":"value"}' ``` The command-line parser stores that token: ```javascript function parseArgs(argv) { const parsed = { operation: null, paramsJson: "{}", token: null }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); } return parsed; } ``` The token is injected into the request parameters: ```javascript function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` All query parameters, including `token`, are then added to the request URL: ```javascript const params = parseParams(args.paramsJson); applyDefaults(operation, params); injectToken(operation, params, args.token); validateRequired(operation, params); const baseUrl = ...[truncated 3379 chars]- Remediation
View remediation
" \ --params-json '{"key":"value"}' ``` 6. **Rotate potentially exposed credentials.** After deploying the hardened implementation, revoke existing tokens that may have appeared in process telemetry or URL logs and issue replacements. ]]>
