T09 · Insecure Skill Coding Practices
- Location
SKILL.md:60- Finding
API Key Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:60-68,bin/run.mjs:240-255, andbin/run.mjs:307-326
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: MediumVulnerable Code
SKILL.md:60bash node {baseDir}/bin/run.mjs --operation "searchMobile" --api-key "$JUST_SERP_API_KEY" --params-json '{"query":"<query>"}'bin/run.mjs:240-255javascript if (!args.apiKey) { fail("Missing required --api-key argument."); } const params = parseParams(args.paramsJson); applyDefaults(operation, params); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", "X-API-Key": args.apiKey, },bin/run.mjs:307-326javascript function parseArgs(argv) { const parsed = { apiKey: null, operation: null, paramsJson: "{}" }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--api-key") { parsed.apiKey = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); }Technical Analysis
The documented invocation expands
JUST_SERP_API_KEYin the shell and passes its value to Node.js as the value of--api-key. The application then obtains the secret fromprocess.argvand places it in the outboundX-API-Keyheader.Although the outbound request uses a fixed HTTPS endpoint, passing a secret through command-line ...[truncated 1641 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the
--api-keycommand-line option and read the credential directly from the environment insiderun.mjs:javascript const apiKey = process.env.JUST_SERP_API_KEY; if (!apiKey) { fail("Missing required JUST_SERP_API_KEY environment variable."); } -
Use the environment-derived value only when constructing the authentication header:
javascript const requestInit = { headers: { accept: "application/json", "X-API-Key": apiKey, }, method: operation.method, }; -
Update the documented invocation so that no secret is included in the argument vector:
bash JUST_SERP_API_KEY="$JUST_SERP_API_KEY" node {baseDir}/bin/run.mjs \ --operation "searchMobile" \ --params-json '{"query":"<query>"}'If the variable is already exported, omit the assignment entirely.
-
Avoid printing the key in errors, debug output, telemetry, or request logs. If request diagnostics are added later, explicitly redact
X-API-Key. -
Rotate any API key suspected of having been exposed through process inspection or command logging, and apply quota and usage alerts to reduce the impact of future disclosure.
-
