T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:76- Finding
API Key Exposed Through Process Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:38,SKILL.md:44,bin/run.mjs:76-78,bin/run.mjs:87-90
Vulnerability Type: API credential exposure through process arguments
Risk Level: MediumVulnerable Code
SKILL.md:38:bash node {baseDir}/bin/run.mjs --operation "markdown" --api-key "$JUST_SERP_API_KEY" --params-json '{"url":"<url>"}'SKILL.md:44:markdown - Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs.bin/run.mjs:76-78:js if (!args.apiKey) { fail("Missing required --api-key argument."); }bin/run.mjs:87-90:js const requestInit = { headers: { "accept": "application/json", "X-API-Key": args.apiKey,Technical Analysis
The documented execution method expands
JUST_SERP_API_KEYinto the value of the--api-keycommand-line argument. The script then consumes that argument and places it in theX-API-Keyrequest header.Environment-variable expansion occurs in the invoking shell before Node.js starts. Consequently, the expanded credential becomes part of the process argument vector. Depending on operating-system permissions and deployment configuration, process arguments may be visible through process inspection interfaces, administrative utilities, monitoring agents, crash diagnostics, audit systems, or orchestration telemetry.
The credential is transmitted to the declared API service over HTTPS, and no evidence shows that the script deliberately logs it. The weakness is specifically the unnecessary placement of the secret in process arguments.
Attack Path
- A victim follows the documented command and invokes the helper with
--api-key "$JUST_SERP_API_KEY". - The shell expands
JUST_SERP_API_KEY, placing the plaintext credential in the Node.js process argument vector. - While the process is running—or through previo ...[truncated 867 chars]
- A victim follows the documented command and invokes the helper with
- Remediation
View remediation
Remediation Suggestions
-
Read the credential directly from the environment rather than accepting it through a command-line argument:
js const apiKey = process.env.JUST_SERP_API_KEY; if (!apiKey) { fail("Missing required JUST_SERP_API_KEY environment variable."); } -
Use the environment-derived value when constructing the request:
js const requestInit = { headers: { "accept": "application/json", "X-API-Key": apiKey, }, method: operation.method, }; -
Remove
--api-keyparsing fromparseArgsand reject command-line credential input to prevent accidental exposure. -
Update the documented invocation to avoid expanding the key into argv:
bash JUST_SERP_API_KEY="$JUST_SERP_API_KEY" node {baseDir}/bin/run.mjs \ --operation "markdown" \ --params-json '{"url":"https://www.example.com"}' -
If environment-based secret injection is unsuitable, accept the credential through a protected file descriptor or a file with restrictive permissions rather than through argv.
-
Ensure monitoring, crash reporting, and audit systems redact API keys and command-line secret flags. Rotate any key suspected of having been captured in process telemetry.
-
