T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:242- Finding
API Token Exposed Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
"}' ``` `bin/run.mjs:23-31`: ```js { "defaultValue": null, "description": "User authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" } ``` `bin/run.mjs:107-109`: ```js applyDefaults(operation, params); injectToken(operation, params, args.token); validateRequired(operation, params); ``` `bin/run.mjs:131`: ```js response = await fetch(url, requestInit); ``` `bin/run.mjs:242-249`: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` ### Technical Analysis The documented invocation expands `JUST_ONE_API_TOKEN` into a `--token` command-line argument. Depending on operating-system configuration and local privileges, command-line arguments can be visible through process inspection tools, process-management interfaces, audit systems, diagnostic tooling, or shell history if users invoke the command with a literal token. The implementation then defines the token as a query parameter and appends it to the request URL. Although the destination is fixed to `https://api.justoneapi.com` and HTTPS protects the request from ordinary network interception, query-string credentials can still be recorded by upstream servers, reverse proxies, gateways, access logs, monitoring systems, error reports, and URL-oriente ...[truncated 1567 chars]- Remediation
View remediation
"}' ``` 5. If the upstream service only supports query-string authentication: - Continue using the fixed HTTPS origin. - Ensure clients, proxies, gateways, and server logs redact the `token` parameter. - Never include the complete request URL in errors or telemetry. - Use short-lived, narrowly scoped tokens and support prompt revocation and rotation. - Clearly document the residual query-string credential exposure. 6. Add automated tests verifying that tokens never appear in standard output, standard error, exception details, telemetry, or serialized request diagnostics. ]]>
