T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:203- Finding
API Key Exposed Through Command-Line Arguments
- Content
View full analysis
"}' ``` ```text - Required: `JUST_SERP_API_KEY` - Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs. ``` ### Technical Analysis The helper requires the Just Serp API key to be supplied through the `--api-key` command-line argument. Shell expansion substitutes `$JUST_SERP_API_KEY` with its actual value before starting Node.js, placing the plaintext credential in the process argument vector. Depending on the operating system, container configuration, and ...[truncated 2147 chars]- Remediation
View remediation
"}' ``` 4. Where environment variables are unsuitable, accept the credential through protected standard input or a secret-manager integration rather than through command-line arguments. 5. Ensure diagnostic, error, and telemetry paths redact `X-API-Key`, `JUST_SERP_API_KEY`, and any legacy `--api-key` values. 6. Rotate any API key that may already have appeared in process telemetry, CI/CD logs, shell traces, or monitoring records. 7. Apply least-privilege service quotas and usage alerts to reduce the impact of future credential exposure. ]]>
