T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:260- Finding
Authentication Token Exposed in URL Query String
- Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` All query parameters, including the token, are then appended to the request URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } function appendValue(searchParams, name, value) { if (Array.isArray(value)) { for (const item of value) { appendValue(searchParams, name, item); } return; } if (value && typeof value === "object") { searchParams.append(name, JSON.stringify(value)); return; } searchParams.append(name, String(value)); } ``` ### Technical Analysis The Skill legitimately requires network access to the fixed HTTPS host `api.justoneapi.com`, and transmitting an authentication credential is necessary for its declared API functionality. There is no evidence that the token is sent to an undeclared destination or covertly exfiltrate ...[truncated 1874 chars]- Remediation
View remediation
