T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:132- Finding
API Token Exposed Through Process Arguments and URL Query Parameters
- Content
View full analysis
"}' ``` ```markdown - Required: `JUST_ONE_API_TOKEN` - Pass the token with `--token "$JUST_ONE_API_TOKEN"`; do not paste token values into chat messages, screenshots, or logs. ``` `bin/run.mjs:75-79` constructs a URL and serializes all query parameters before issuing the network request: ```js const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); ``` `bin/run.mjs:132-152` accepts the token directly from the process argument vector: ```js function parseArgs(argv) { const parsed = { operation: null, paramsJson: "{}", token: null }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); } return parsed; } ``` `bin/run.mjs:174-186` copies the command-line secret into the request parameter collection: ```js function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { ...[truncated 3689 chars]- Remediation
View remediation
"}' ``` 2. **Prefer header-based authentication.** If supported by JustOneAPI, transmit the credential in an authorization header rather than the query string: ```js const requestInit = { headers: { accept: "application/json", authorization: `Bearer ${token}`, }, method: operation.method, }; ``` Ensure `token` is excluded from `applyQueryParams`. 3. **If query authentication is an unavoidable upstream requirement:** - Confirm that client, proxy, CDN, API gateway, server, tracing, and analytics configurations redact the `token` parameter. - Disable full-URL logging where possible. - Ensure redirects are disabled or carefully constrained so the credential cannot be forwarded to another origin. - Avoid including the constructed URL in exceptions, diagnostics, or debug output. - Use short-lived, narrowly scoped, and readily revocable tokens. - Document the residual logging risk for users. 4. **Prevent alternate token injection through `--params-json`.** Reject `token` in user-provided parameters and source it exclusively from the protected credential channel: ```js if (Object.prototype.hasOwnProperty.call(params, "token")) { fail("The token must not be supplied through --params-json."); } ``` 5. **Rotate potentially exposed credentials.** Users who have executed the documented command should review process telemetry and shell-audit systems and rotate the token if command lines may have been retained. ]] ...[truncated 1 chars]
