T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:82- Finding
API Key Exposed Through Command-Line Arguments
- Content
View full analysis
"}' ``` The implementation requires and parses that command-line argument: ```javascript if (!args.apiKey) { fail("Missing required --api-key argument."); } ``` ```javascript if (flag === "--api-key") { parsed.apiKey = value; index += 1; continue; } ``` ### Technical Analysis Although the key originates in an environment variable, the documented shell command expands its value into the Node process argument vector. Command-line arguments may be visible to other sufficiently privileged local users, process-inspection utilities, monitoring agents, diagnostic systems, container orchestration telemetry, or command-auditing infrastructure. The warning in `SKILL.md` not to paste API keys into logs does not prevent this exposure because the prescribed invocation itself places the plaintext credential in process metadata. The code offers no safer authentication input mechanism, such as reading `JUST_SERP_API_KEY` directly from `process.env` or accepting the credential through protected standard input. ### Attack Path 1. A user configures `JUST_SERP_API_KEY` and invokes the helper using the documented command. 2. The shell expands `$JUST_SERP_API_KEY` into the plaintext `--api-key` argument. 3. While the process is running, or if process execution is recorded, a local observer or monitoring system captures the command line. 4. The observer extracts the API key from the argument following `--api-key`. 5. The exposed credential is replayed against the Just Serp API. Exploitation requires access to process metadata, ...[truncated 638 chars]- Remediation
View remediation
"}' ``` When the environment is already configured, the command should omit the inline assignment entirely. 5. Ensure error messages, debug output, process telemetry, and HTTP diagnostics never serialize the API key or complete request headers. 6. Recommend rotating the API key if it has previously been used through the documented `--api-key` interface in an environment where process arguments are logged or observable. ]]>
