T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:129- Finding
API Token Exposure Through Process Arguments and URL Query Parameters
- Content
View full analysis
- Remediation
View remediation
`, or the service's documented private authentication header. - Remove the token from `operation.parameters` and ensure it cannot be processed by `applyQueryParams()`. 3. **If the upstream service strictly requires query authentication:** - Retain HTTPS and keep the destination host fixed. - Read the token directly from the environment rather than accepting it through the CLI. - Ensure proxies, gateways, servers, and observability tools redact the `token` query parameter. - Never include the constructed URL, query string, or token in errors, traces, analytics, or debug logs. - Request support for header-based credentials from the API provider. 4. **Harden token handling.** - Validate that the token is non-empty without printing it. - Keep tokens short-lived and narrowly scoped where the provider supports those controls. - Rotate any token that may already have appeared in process or request logs. - Restrict access to execution telemetry and API infrastructure logs. 5. **Update the documentation.** - Replace the documented `--token "$JUST_ONE_API_TOKEN"` invocation with automatic environment loading. - Explicitly warn users not to place tokens in `--params-json`, chat messages, screenshots, shell history, or logs. ]]>
