T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:20- Finding
API Token Exposure Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` All parameters marked as query parameters—including the token—are appended to the URL before the network request: ```javascript applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, }; if (operation.requestBody && params.body !== undefined) { requestInit.body = JSON.stringify(params.body); requestInit.headers["content-type"] = operation.requestBody.contentType || "application/json"; } let response; try { response = await fetch(url, requestInit); } catch (error) { fail("Network request failed.", { cause: error instanceof Error ? error.message : String(error), operationId: operation.operationId, }); } ``` ```javascript function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) ...[truncated 3072 chars]- Remediation
View remediation
