T09 · Insecure Skill Coding Practices
- Location
SKILL.md:42- Finding
API Key Exposure Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 42
Related Code:bin/run.mjs, lines 89–91 and 147–162
Vulnerability Type: API credential exposure through process arguments
Risk Level: MediumVulnerable Code
bash node {baseDir}/bin/run.mjs --operation "patentDetails" --api-key "$JUST_SERP_API_KEY" --params-json '{"patent_id":"<patent_id>"}'The helper parses the expanded credential from the command line and places it in an HTTP header:
js const requestInit = { headers: { "accept": "application/json", "X-API-Key": args.apiKey, }, method: operation.method, };js if (flag === "--api-key") { parsed.apiKey = value; index += 1; continue; }Technical Analysis
Although the credential originates in the
JUST_SERP_API_KEYenvironment variable, the documented command expands its value into the Node.js process argument vector. Command-line arguments can be exposed through process-inspection interfaces, diagnostic and monitoring tools, shell tracing, audit systems, or logs that record complete commands.The implementation requires this insecure credential transport instead of reading the already-declared environment variable inside the process. Exploitation requires local process-observation capability or access to telemetry that captures command lines; no remote exploitation path was identified.
Attack Path
- A victim configures
JUST_SERP_API_KEYand invokes the helper using the documented command. - The shell expands
"$JUST_SERP_API_KEY"into the value supplied to--api-key. - The secret becomes part of the Node.js process argument vector.
- A local user, monitoring component, audit collector, or diagnostic tool with permission to inspect command lines captures the argument.
- The observer extracts and reuses the API key against the Just Serp API.
Impact Assessment
Successful exploitation discloses the Just Serp API credential. An attacker could make authenticated ...[truncated 382 chars]
- A victim configures
- Remediation
View remediation
Remediation Suggestions
- Remove the
--api-keycommand-line option and read the declared environment variable directly:
js const apiKey = process.env.JUST_SERP_API_KEY; if (!apiKey) { fail("Missing required JUST_SERP_API_KEY environment variable."); }- Use the internally loaded value only when constructing the request header:
js const requestInit = { headers: { accept: "application/json", "X-API-Key": apiKey, }, method: operation.method, };- Update the documented invocation so the secret is not included in the argument vector:
bash node {baseDir}/bin/run.mjs --operation "patentDetails" --params-json '{"patent_id":"<patent_id>"}'-
If explicit credential injection is required, use standard input or a permission-restricted credential source rather than process arguments.
-
Ensure application logs, shell tracing, diagnostics, and error output never record API-key values. Rotate any credential that may previously have been exposed through command-line capture.
- Remove the
