T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:22- Finding
API Token Transmitted in the URL Query String
- Content
View full analysis
Vulnerability Details
File Location:
bin/run.mjs:22-30,bin/run.mjs:83-85,bin/run.mjs:205-212
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: MediumVulnerable Code
js { "defaultValue": null, "description": "User authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" }js const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url);js function appendValue(searchParams, name, value) { if (Array.isArray(value)) { for (const item of value) { appendValue(searchParams, name, item); } return; } if (value && typeof value === "object") { searchParams.append(name, JSON.stringify(value)); return; } searchParams.append(name, String(value)); }Technical Analysis
The authentication token is declared as a query parameter. After
injectToken()places the credential inparams.token,applyQueryParams()passes it toappendValue(), which adds it to the URL. The resulting request therefore contains the credential in a form equivalent to:text https://api.justoneapi.com/api/.../v1?token=REDACTED&userId=USER_IDHTTPS protects the URL while it is in transit, but it does not prevent the complete URL from being recorded by the destination service, API gateways, reverse proxies, observability systems, network diagnostics, or error-reporting infrastructure. Query-string credentials are consequently more likely to leak into retained logs than credentials sent through an authentication header.
The destination is hard-coded to the declared
https://api.justoneapi.comservice, and the token is required to use that service. This is therefore not evidence of covert exfiltration or an unauthorized de ...[truncated 1192 chars]- Remediation
View remediation
Remediation Suggestions
-
Replace query-string authentication with a provider-supported authentication header, preferably:
js const requestInit = { headers: { accept: "application/json", authorization: `Bearer ${token}`, }, method: operation.method, }; -
Remove
tokenfrom the operation's ordinary query parameters so it cannot be appended to the URL accidentally. -
If JustOneAPI supports another dedicated authentication header, use that header according to its official specification.
-
Configure application, gateway, proxy, monitoring, and error-reporting systems to redact authorization credentials and sensitive query parameters.
-
If the upstream API exclusively requires query authentication, use short-lived, narrowly scoped tokens and explicitly document the residual URL-logging risk.
-
Implement prompt token revocation and rotation procedures for suspected exposure.
-
