T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:91- Finding
API Token Exposed Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
"}' ``` The operation manifest defines the token as a required query parameter: ```js { "defaultValue": null, "description": "User authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" } ``` The executable injects the supplied credential into the request parameters: ```js const params = parseParams(args.paramsJson); applyDefaults(operation, params); injectToken(operation, params, args.token); validateRequired(operation, params); ``` All parameters whose location is `query`, including the token, are appended to the URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The generated specification confirms this behavior in `generated/operations.json:15-23` and `generated/operations.md:19`. ### Technical Analysis Passing the credential using `--token "$JUST_ONE_API_TOKEN"` expands the secret into the process argument vector. Depending on operating-system configuration and execution environment, command-line arguments may be visible through process inspection, shell or orchestration telemetry, diagnostic tooling, and execution wrappers. The token is then inserted into the HTTPS URL as a query parameter. TLS protects the request while it is transported across the network, but it ...[truncated 2028 chars]- Remediation
View remediation
"}' ``` Prefer supplying the environment variable through a secure secret manager rather than inline shell history. 5. If the upstream service only supports query-string authentication: - Document that constraint and its residual risk. - Use narrowly scoped, short-lived tokens. - Configure gateways, proxies, access logs, telemetry, and error reporting to redact the `token` query parameter. - Avoid logging request URLs or exception objects that may include the URL. - Rotate any token suspected of having appeared in process or URL logs. ]]>
