T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:17- Finding
API Credential Exposure Through Query-String Authentication and Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
bin/run.mjs:17-26,bin/run.mjs:67-82,bin/run.mjs:172-184,bin/run.mjs:224-238, andSKILL.md:41-49
Vulnerability Type: API credential exposure
Risk Level: MediumVulnerable Code
The operation metadata defines the authentication token as a query parameter:
js { "defaultValue": null, "description": "User authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" }The token is injected into the parameter collection and subsequently appended to the request URL:
js const params = parseParams(args.paramsJson); applyDefaults(operation, params); injectToken(operation, params, args.token); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, }; let response; try { response = await fetch(url, requestInit);js function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; }js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } function appendValue(searchParams, name, value) ...[truncated 3833 chars]- Remediation
View remediation
Remediation Suggestions
-
Move authentication out of the URL. If supported by JustOneAPI, transmit the credential in an authorization header:
js const token = args.token || process.env.JUST_ONE_API_TOKEN; if (!token) { fail("JUST_ONE_API_TOKEN is required."); } const requestInit = { method: operation.method, headers: { accept: "application/json", authorization: `Bearer ${token}`, }, }; -
Read the token directly from the environment. Prefer
process.env.JUST_ONE_API_TOKENand remove the documented--tokenargument to reduce exposure through process listings and execution telemetry. -
Prevent credentials from entering generic parameter handling. Remove
tokenfromoperation.parametersand do not store it in the same object as ordinary query parameters. -
Implement explicit redaction. Ensure request logging, errors, traces, and telemetry replace token values with a fixed marker. Never print fully constructed URLs containing authentication material.
-
If query authentication is mandated by the remote API, document the residual risk, request header-based authentication support from the provider, disable query-string logging where possible, tightly restrict access to proxy and server logs, shorten log retention, and use narrowly scoped, short-lived tokens.
-
Rotate potentially exposed credentials. Revoke and replace tokens that may already have appeared in process metadata or URL logs. Monitor account activity for unauthorized requests and quota anomalies.
-
