T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:100- Finding
API Credential Exposed Through Command-Line Arguments and URL Query Parameters
- Content
View full analysis
"}' ``` `bin/run.mjs:22-29` declares the token as a query parameter: ```js { "defaultValue": null, "description": "TOKEN", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" }, ``` `bin/run.mjs:100-111` injects the token into the parameters and constructs the request URL: ```js const params = parseParams(args.paramsJson); applyDefaults(operation, params); injectToken(operation, params, args.token); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, }; ``` `bin/run.mjs:242-250` serializes every query parameter, including `token`, into the URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` ### Technical Analysis Authentication is necessary for the declared JustOneAPI functionality, and the credential is sent only to the fixed, documented HTTPS destination `https://api.justoneapi.com`. The audit found no evidence that the token is deliberately sent to an unrelate ...[truncated 2471 chars]- Remediation
View remediation
