T09 · Insecure Skill Coding Practices
- Location
SKILL.md:52- Finding
API Key Exposed Through Command-Line Arguments
- Content
View full analysis
"}' ``` The environment instructions explicitly require this invocation pattern: ```markdown - Required: `JUST_SERP_API_KEY` - Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs. ``` The helper requires the command-line API key and subsequently places it in the request header: ```javascript if (!args.apiKey) { fail("Missing required --api-key argument."); } const params = parseParams(args.paramsJson); applyDefaults(operation, params); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", "X-API-Key": args.apiKey, }, method: operation.method, }; ``` ### Technical Analysis Shell expansion of `"$JUST_SERP_API_KEY"` occurs before Node.js starts. The resulting plaintext credential is placed in the process argument vector as the value of `--api-key`. Depending on operating-system access controls and deployment configuration, command-line arguments may be visible through process inspection utilities, process metadata interfaces, monitoring agents, diagnostic tools, crash collectors, audit systems, or command execution logs. This creates a credential-disclosure channel even though the key is not printed by the application itself. The implementation also requires `args.apiKey`, making the insecure command-line mechanism the expected authen ...[truncated 1910 chars]- Remediation
View remediation
"}' ``` If the variable is already exported, it does not need to appear in the invocation: ```bash node {baseDir}/bin/run.mjs \ --operation "shortsSearch" \ --params-json '{"query":""}' ``` 4. If explicit credential injection is necessary, accept it through protected standard input, a permission-restricted file descriptor, or a platform secret manager rather than through command-line arguments. 5. Ensure error handling, debug output, telemetry, and request logging redact the `X-API-Key` header and the `JUST_SERP_API_KEY` value. 6. Deprecate and reject `--api-key` to prevent users from continuing to expose credentials through legacy invocation patterns. 7. Rotate any API key previously used through this command if process arguments may have been captured by shared-host users, monitoring systems, or execution logs. ]]>
