T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:157- Finding
API Key Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:45-51,bin/run.mjs:86-88,bin/run.mjs:157-160
Vulnerability Type: API credential exposure through the process argument vector
Risk Level: MediumVulnerable Code
The documented invocation passes the API key as a command-line argument:
bash node {baseDir}/bin/run.mjs --operation "financeSearch" --api-key "$JUST_SERP_API_KEY" --params-json '{"query":"<query>"}'The documentation explicitly requires this command-line pattern:
markdown - Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs.The implementation requires and parses the secret from the process arguments:
js if (!args.apiKey) { fail("Missing required --api-key argument."); }js if (flag === "--api-key") { parsed.apiKey = value; index += 1; continue; }Technical Analysis
Although the key originates in an environment variable, the shell expands
"$JUST_SERP_API_KEY"before launching Node.js. The resulting secret is therefore placed in the child process's argument vector as the value of--api-key.Process arguments can be exposed through operating-system process inspection interfaces, administrative monitoring, endpoint telemetry, crash diagnostics, command auditing, or process-management tools. Exposure depends on the host's process isolation and monitoring configuration, but passing credentials through command-line arguments unnecessarily increases their observable surface.
The key is subsequently used as an
X-API-Keyheader for the fixed HTTPS endpoint. No evidence was found that the script intentionally logs the key, sends it to an undeclared destination, or embeds a hardcoded credential.Attack Path
- A user follows the documented command and invokes the helper with
--api-key "$JUST_SERP_API_KEY". - The shell expands
JUST_SERP_API_KEYand places its value in the Node.js process argument vector.
...[truncated 988 chars]
- A user follows the documented command and invokes the helper with
- Remediation
View remediation
Remediation Suggestions
- Remove the
--api-keycommand-line option and read the credential directly from the environment:
js const apiKey = process.env.JUST_SERP_API_KEY; if (!apiKey) { fail("Missing required JUST_SERP_API_KEY environment variable."); }- Use the environment-derived value only when constructing the request header:
js const requestInit = { headers: { accept: "application/json", "X-API-Key": apiKey, }, method: operation.method, };- Update the documented invocation so the secret is not expanded into the command line:
bash JUST_SERP_API_KEY="$JUST_SERP_API_KEY" \ node {baseDir}/bin/run.mjs \ --operation "financeSearch" \ --params-json '{"query":"<query>"}'If the variable is already exported, omit the inline assignment entirely.
-
For environments where environment-variable exposure is also considered too broad, support protected standard input or an operating-system secret store. Do not accept the secret in a URL, query string, or ordinary command-line flag.
-
Avoid including the API key in error objects, debug logs, telemetry, or crash reports. Consider redaction controls for both
X-API-KeyandJUST_SERP_API_KEY. -
After deploying the fix, rotate any credential that may have been captured in process telemetry or historical command-line records.
- Remove the
