T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:188- Finding
API Key Exposed Through Process Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:46,52;bin/run.mjs:105-107,188-192
Vulnerability Type: API key exposure through process arguments
Risk Level: MediumThe documented invocation passes the Just Serp API key as a command-line argument:
bash node {baseDir}/bin/run.mjs --operation "aiMode" --api-key "$JUST_SERP_API_KEY" --params-json '{"query":"<query>"}'The documentation explicitly directs users to use the affected argument:
markdown - Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs.The executable requires and parses that argument:
js if (!args.apiKey) { fail("Missing required --api-key argument."); }js if (flag === "--api-key") { parsed.apiKey = value; index += 1; continue; }Technical Analysis
Although the key originates in an environment variable, shell expansion places its value directly in the Node process argument vector. Depending on operating-system configuration, command-line arguments can be observed through process-listing utilities, process metadata interfaces, diagnostic tools, monitoring agents, shell tracing, or command-execution logs.
The implementation does not print the key itself, and it sends the credential only to the fixed HTTPS API endpoint. Nevertheless, using an argument for secret transport unnecessarily increases local exposure compared with reading the existing
JUST_SERP_API_KEYenvironment variable directly.Exploitation requires local process-observation access or access to tooling that records command lines. No evidence was found that this issue enables remote code execution, privilege escalation, persistence, or arbitrary access to unrelated credentials.
Attack Path
- A user exports a valid value in
JUST_SERP_API_KEY. - The user invokes the helper using the command documented in
SKILL.md. - The ...[truncated 902 chars]
- A user exports a valid value in
- Remediation
View remediation
Remediation Suggestions
-
Remove
--api-keyfrom the documented invocation and read the declared environment variable directly:js const apiKey = process.env.JUST_SERP_API_KEY; if (!apiKey) { fail("Missing required JUST_SERP_API_KEY environment variable."); } -
Use
apiKeyonly when constructing the request header:js const requestInit = { headers: { accept: "application/json", "X-API-Key": apiKey, }, method: operation.method, }; -
Remove API-key handling from
parseArgsso the secret cannot accidentally be supplied through the process argument vector. -
Update
SKILL.mdto use the following form:bash JUST_SERP_API_KEY="$JUST_SERP_API_KEY" node {baseDir}/bin/run.mjs --operation "aiMode" --params-json '{"query":"<query>"}'Prefer invoking the command from an environment where the variable is already exported, avoiding redundant assignment on the command line.
-
Ensure errors, debug output, telemetry, and request logging never serialize request headers or the environment variable.
-
Rotate any API key that may already have been captured by process-monitoring or command-recording systems, and review account usage for unauthorized requests.
-
