T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:155- Finding
API Key Exposure Through Command-Line Arguments
- Content
View full analysis
"}' ``` `SKILL.md:51`: ```markdown - Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs. ``` ### Technical Analysis The helper requires the Just Serp API key to be supplied using the `--api-key` command-line option. Although the documentation references an environment variable, the shell expands `$JUST_SERP_API_KEY` before launching Node.js, placing the resulting secret directly in the child process argument vector. Command-line arguments may be observable through process inspection facilities, process-monitoring software, diagnostic tooling, CI/CD command tracing, endpoint telemetry, crash reports, or process-launch audit records. The documentation warning against pasting the key into logs does not prevent these indirect disclosure channels. The key is subsequently used as the `X-API-Key` header for requests to `https://api.justserpapi.com`. The network transmission itself uses HTTPS and no evidence of transmission to an un ...[truncated 1453 chars]- Remediation
View remediation
"}' ``` 5. Where environment inheritance is unsuitable, accept credentials through protected standard input or a credential file restricted to the owning user. 6. Ensure error messages, debug output, telemetry, and request logging redact `X-API-Key`. 7. Rotate any credential that may already have been exposed through shell history, process telemetry, CI logs, or monitoring records. ]]>
