T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:23- Finding
API Credential Exposed Through Command-Line Arguments and URL Query String
- Content
View full analysis
item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The documented invocation also puts the credential in a command-line argument: ```bash node {baseDir}/bin/run.mjs --operation "getColumnArticleDetailV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"id":""}' ``` ### Technical Analysis The helper accepts the API credential through `--token`, copies it into `params.token`, and treats `token` as a query parameter. The resulting request has the effective form: ```text https://api.justoneapi.com/api/zhihu/get-column-article-detail/v1?token=&id= ``` This creates two credential-exposure surfaces: 1. **Process ...[truncated 2356 chars]- Remediation
View remediation
