T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:69- Finding
API Key Exposed Through Process Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:44,SKILL.md:49,bin/run.mjs:69-71, andbin/run.mjs:86
Vulnerability Type: Credential exposure through process arguments
Risk Level: MediumVulnerable Code
SKILL.md:44:bash node {baseDir}/bin/run.mjs --operation "mapsPosts" --api-key "$JUST_SERP_API_KEY" --params-json '{"data_id":"<data_id>"}'SKILL.md:49:markdown - Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs.bin/run.mjs:69-71:js if (!args.apiKey) { fail("Missing required --api-key argument."); }bin/run.mjs:83-89:js const requestInit = { headers: { "accept": "application/json", "X-API-Key": args.apiKey, }, method: operation.method, };Technical Analysis
The documented invocation expands
JUST_SERP_API_KEYinto the--api-keycommand-line argument before Node starts. Consequently, the plaintext credential becomes part of the process argument vector.On systems where process metadata is visible to other users, administrators, monitoring agents, diagnostic collectors, audit tooling, or process supervisors, the key may be captured through process-list inspection or command-line telemetry. Although the script does not deliberately print the key and transmits it only to the declared HTTPS API endpoint, using an argument as the credential transport unnecessarily increases its local exposure.
The executable requires
args.apiKeyand places that value in theX-API-Keyrequest header. The security issue is not the authenticated HTTPS header itself; it is the earlier delivery of the secret through a command-line argument.Attack Path
- A legitimate user launches the documented command with
--api-key "$JUST_SERP_API_KEY". - The shell expands the environment variable into its plaintext value.
- The expanded key ...[truncated 1144 chars]
- A legitimate user launches the documented command with
- Remediation
View remediation
Remediation Suggestions
-
Read the credential directly from the environment rather than requiring it as a command-line argument:
js const apiKey = process.env.JUST_SERP_API_KEY; if (!apiKey) { fail("Missing required JUST_SERP_API_KEY environment variable."); } const requestInit = { headers: { accept: "application/json", "X-API-Key": apiKey, }, method: operation.method, }; -
Remove support for
--api-keyfromparseArgsso users are not encouraged to expose credentials through the process argument vector. -
Update the documented command to omit the credential argument:
bash JUST_SERP_API_KEY="..." node {baseDir}/bin/run.mjs \ --operation "mapsPosts" \ --params-json '{"data_id":"<data_id>"}'Prefer setting the variable through the user's protected environment or secret manager rather than placing the assignment directly in interactive shell history.
-
If an explicit credential channel is necessary, accept it through protected standard input, an operating-system secret store, or a permission-restricted credential file.
-
Ensure errors, debug logs, telemetry, and exception objects never include the key or complete request headers.
-
Rotate any credential that may already have been exposed through command-line history, process monitoring, or diagnostic collection.
-
