T09 · Insecure Skill Coding Practices
- Location
SKILL.md:42- Finding
API Token Exposed Through Command-Line Arguments
- Content
View full analysis
"}' ``` ```js if (flag === "--token") { parsed.token = value; index += 1; continue; } ``` ### Technical Analysis The documented invocation passes the JustOneAPI authentication token through the `--token` command-line argument. The helper explicitly parses and retains this argument. Command-line arguments may be visible to other local users or monitoring systems through process inspection, shell auditing, command histories, crash diagnostics, process telemetry, and automation logs. Expanding an environment variable into an argument does not preserve its confidentiality after process creation. This behavior exceeds the minimum privilege necessary for reading the configured `JUST_ONE_API_TOKEN` environment variable. The Skill metadata already declares that environment variable as required, so the helper could read it directly without placing the secret in the process argument vector. ### Attack Path 1. A user follows the command documented in `SKILL.md`. 2. The shell expands `$JUST_ONE_API_TOKEN` into the Node process argument list. 3. While the helper is running, a local observer or process-monitoring service records the command line. 4. The observer extracts the value following `--token`. 5. The exposed token is reused against JustOneAPI within the permissions and lifetime assigned to that credential. ### Impact Assessment Successful exploitation discloses the JustOneAPI authentication token. An attacker could consume the associated API quota and invoke API operations authorized for that token. The exact accessible data and operations depend on server-side token scope; the audited code does not establis ...[truncated 260 chars]- Remediation
View remediation
"}' ``` 3. Ensure deployment wrappers, debug output, process telemetry, and error handlers never record the token. 4. Rotate any token that may already have appeared in process-monitoring, shell-audit, or automation logs. 5. Where supported, use short-lived, narrowly scoped credentials to reduce the impact of accidental disclosure. ]]>
