T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:164- Finding
API Key Exposed Through Command-Line Arguments
- Content
View full analysis
"}' ``` ### Technical Analysis The shell expands `$JUST_SERP_API_KEY` before starting Node.js, placing the plaintext API key in the new process's argument vector. Depending on operating-system access controls and the execution environment, command-line arguments may be visible through process inspection interfaces, process-monitoring agents, audit logs, debugging tools, shell tracing, or orchestration telemetry. Although the key is subsequently sent to the intended service through the `X-API-Key` HTTPS header, accepting it through `--api-key` creates an unnecessary local disclosure channel. This also conflicts with the documentation's stated goal of preventing API keys from appearing in logs. ### Attack Path 1. A victim follows the documented command and supplies `JUST_SERP_API_KEY` through `--api-key`. 2. The shell expands the environment variable into the plaintext process argument vector. 3. While the helper is running, an attacker or monitoring compone ...[truncated 968 chars]- Remediation
View remediation
"}' ``` Where possible, inject the environment variable through a secret manager or protected runtime configuration rather than defining it inline. 4. Reject `--api-key` explicitly so users do not continue exposing credentials through legacy commands. 5. Avoid logging request headers, environment values, or complete process arguments. 6. Rotate any API key that may previously have been captured through process monitoring, command auditing, or shell tracing. 7. If environment-based secret injection is unavailable, accept the secret through protected standard input or an operating-system secret store rather than through command-line arguments. ]]>
