T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:1481- Finding
API Token Exposed Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
" --token "$JUST_ONE_API_TOKEN" --params-json '{"key":"value"}' ``` `bin/run.mjs:1481-1503`: ```javascript injectToken(operation, params, args.token); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, }; if (operation.requestBody && params.body !== undefined) { requestInit.body = JSON.stringify(params.body); requestInit.headers["content-type"] = operation.requestBody.contentType || "application/json"; } let response; try { response = await fetch(url, requestInit); ``` `bin/run.mjs:1558-1559`: ```javascript if (flag === "--token") { parsed.token = value; ``` `bin/run.mjs:1590-1600`: ```javascript function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; ``` `bin/run.mjs:1637-1651`: ```javascript function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } func ...[truncated 3576 chars]- Remediation
View remediation
" \ --params-json '{"key":"value"}' ``` 6. **Credential response** - Rotate tokens that may already have appeared in process telemetry, shell traces, proxy logs, or URL access logs. - Review retained logs for unauthorized disclosure and subsequent token use. ]]>
