T09 · Insecure Skill Coding Practices
- Location
SKILL.md:49- Finding
API Key Exposed Through Process Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:49,SKILL.md:57,bin/run.mjs:129,bin/run.mjs:139-156, andbin/run.mjs:217-227
Vulnerability Type: API credential exposure through process arguments
Risk Level: MediumThe documented invocation expands
JUST_SERP_API_KEYinto the command line:bash node {baseDir}/bin/run.mjs --operation "TrendsSearch" --api-key "$JUST_SERP_API_KEY" --params-json '{"query":"<query>"}'The accompanying documentation explicitly directs users to pass the credential this way:
markdown - Required: `JUST_SERP_API_KEY` - Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs.The executable reads the API key from
process.argvand places it into the request header:javascript const args = parseArgs(process.argv.slice(2)); if (!args.apiKey) { fail("Missing required --api-key argument."); } const requestInit = { headers: { "accept": "application/json", "X-API-Key": args.apiKey, }, method: operation.method, };The argument parser confirms that the secret is accepted directly as an argument:
javascript function parseArgs(argv) { const parsed = { apiKey: null, operation: null, paramsJson: "{}" }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--api-key") { parsed.apiKey = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); } return parsed; }Technical Analysis
Passing a secret through a command-line argument places the expanded cr ...[truncated 1971 chars]
- Remediation
View remediation
Remediation Suggestions
-
Read the credential directly from the environment rather than from
process.argv:javascript const apiKey = process.env.JUST_SERP_API_KEY; if (!apiKey) { fail("Missing required JUST_SERP_API_KEY environment variable."); } const requestInit = { headers: { accept: "application/json", "X-API-Key": apiKey, }, method: operation.method, }; -
Remove
--api-keyfrom the documented command and use:bash JUST_SERP_API_KEY="..." node {baseDir}/bin/run.mjs \ --operation "TrendsSearch" \ --params-json '{"query":"<query>"}'Prefer setting the environment variable through a protected secret manager rather than placing the assignment directly in interactive shell history.
-
Remove or explicitly reject the
--api-keyargument so callers do not continue using the insecure interface. -
If environment-based secret injection is unavailable, accept the key through protected standard input or a permission-restricted credential file. Do not echo the value or include it in error output.
-
Configure CI/CD systems and observability agents to redact
JUST_SERP_API_KEY,X-API-Key, and equivalent credential fields. -
Rotate any API key that may previously have been exposed through process listings, command telemetry, shell tracing, or diagnostic logs.
-
