T09 · Insecure Skill Coding Practices
- Location
SKILL.md:18- Finding
OAuth Client Secret Exposed Through Command-Line Arguments
- Content
View full analysis
``` ### Technical Analysis The documented setup procedure instructs users to supply the TickTick OAuth client secret directly as a command-line argument. Secrets passed this way may be exposed through: - Shell history files and history synchronization systems - Process listings or process-monitoring utilities while the command is running - Terminal session recordings - Command auditing and endpoint telemetry - Diagnostic logs that capture complete command lines The project contains only documentation, so the behavior of the referenced `ticktick-setup` executable and its subsequent token-storage mechanism could not be verified. Nevertheless, the documented invocation itself creates a credential-exposure risk. ### Attack Path 1. A user follows the documented setup procedure and executes `ticktick-setup` with the real OAuth client secret as an argument. 2. The command, including the secret, is retained in shell history, monitoring telemetry, an audit log, or a terminal recording, or is observed through process inspection while running. 3. An attacker with access to that local account, log source, monitoring system, or process metadata retrieves the client secret. 4. The attacker uses the exposed secret to impersonate the registered OAuth client in applicable TickTick OAuth interactions. ### Impact Assessment Exposure compromises the confidentiality of the TickTick application's OAuth client credential. An attacker may impersonate the OAuth application or abuse OAuth flows associated with that client, subject to TickTick's authorization controls and the attacker's possession of any other required authorization artifacts. The secret alone is not demonstrated to grant ...[truncated 324 chars]- Remediation
View remediation
# The program then securely prompts for the client secret without echoing it. ``` - Document how OAuth tokens and client credentials are stored, encrypted, rotated, and revoked. - Advise users who already followed the original command to remove affected shell-history entries and rotate the exposed OAuth client secret. ]]>
