T09 · Insecure Skill Coding Practices
- Location
SKILL.md:41- Finding
API Key Exposed Through Command-Line Arguments
- Content
View full analysis
"}' ``` `bin/run.mjs:81` parses the process argument vector: ```js const args = parseArgs(process.argv.slice(2)); ``` `bin/run.mjs:91-93` requires the command-line API-key value: ```js if (!args.apiKey) { fail("Missing required --api-key argument."); } ``` `bin/run.mjs:101` places that value in the outbound authentication header: ```js "X-API-Key": args.apiKey, ``` The relevant argument parser in `bin/run.mjs:158-181` confirms that the secret is accepted from `--api-key`: ```js function parseArgs(argv) { const parsed = { apiKey: null, operation: null, paramsJson: "{}" }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--api-key") { parsed.apiKey = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); } return parsed; } ``` ### Technical Analysis Although the key originates in the `JUST_SERP_API_KEY` environment variable, the documented shell command expands it into the Node.js process argument vector. Command-line arguments may be exposed through operating-system process inspection facilities, process listings, diagnostic tooling, monitoring agents, shell tracing, or execution telemetry. The outbound request itself uses a fixed HTTPS origin, and no ev ...[truncated 1435 chars]- Remediation
View remediation
"}' ``` If the environment is already configured, the shorter preferred invocation is: ```bash node {baseDir}/bin/run.mjs \ --operation "TrendsTrendingNow" \ --params-json '{"geo":""}' ``` 5. Avoid printing the key in errors or debug logs. Document that shell tracing should be disabled when configuring credentials. 6. Rotate any API key that may previously have been exposed through process listings, telemetry, or command-history recording. ]]>
