T09 · Insecure Skill Coding Practices
- Location
SKILL.md:20- Finding
OAuth Client Secret Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 20
Vulnerability Type: Sensitive information exposure through process arguments and shell history
Risk Level: MediumAffected Code:
bash ticktick-setup <client_id> <client_secret>Technical Analysis
The documented setup procedure instructs users to provide the TickTick OAuth client secret as a command-line argument. Command-line arguments can be exposed through process inspection facilities such as
ps,/proc/<pid>/cmdline, process-monitoring software, terminal logging, and audit services. The command may also be retained in the user's shell history.Consequently, another local user or process with permission to inspect the command line or read the relevant history and logging data could recover the OAuth application secret. This is an insecure secret-handling practice because sensitive credentials should be supplied through a protected interactive prompt, restricted configuration file, operating-system credential store, or another channel that does not expose them in the process argument list.
Attack Path
- A user follows the documented setup command and places the real OAuth client secret in the
<client_secret>argument. - While
ticktick-setupis running, a local attacker or monitoring process observes its command-line arguments through process inspection. - Alternatively, the attacker later obtains access to shell history, terminal logs, audit records, or command telemetry containing the invocation.
- The attacker extracts the TickTick OAuth client ID and client secret.
- The attacker may impersonate the registered OAuth client in flows accepted by the provider. Account access would additionally depend on obtaining authorization codes, redirect-flow access, or tokens; the documentation alone does not establish that the client secret grants direct access to user tasks.
Impact Assessment
Succ ...[truncated 457 chars]
- A user follows the documented setup command and places the real OAuth client secret in the
- Remediation
View remediation
Remediation Suggestions
- Change
ticktick-setupto request the client secret through an interactive, non-echoing prompt rather than a positional command-line argument. - Support loading the secret from an operating-system credential manager or a configuration file readable only by the owning user, such as a file with mode
0600. - If environment-variable input is supported for automation, document that it can still be exposed through process inspection, crash reports, or CI logs and should be handled as a secret by the execution environment.
- Ensure setup code never logs, prints, or persists the raw client secret in plaintext.
- Update the documented invocation to a form such as:
bash ticktick-setup --client-id <client_id> # The program securely prompts for the client secret. - Advise users who already followed the documented command to remove affected shell-history entries, review relevant logs, and rotate the OAuth client secret through the TickTick developer console.
- Change
