T09 · Insecure Skill Coding Practices
- Location
scripts/generate_memorable_image.py:21- Finding
Gemini API Key Exposed Through Process Arguments and URL Query Parameters
- Content
View full analysis
str: if cli_key: return cli_key env_key = os.environ.get("GEMINI_API_KEY") if env_key: return env_key config_path = Path.home() / ".config" / "gemini" / "api_key" if config_path.exists(): return config_path.read_text().strip() print( "Error: Gemini API key not found.\n" "Provide it via --api-key, the GEMINI_API_KEY environment variable,\n" "or by writing it to ~/.config/gemini/api_key", file=sys.stderr, ) sys.exit(1) def generate_image(prompt: str, api_key: str) -> bytes | None: url = ( "https://generativelanguage.googleapis.com/v1beta/models/" f"gemini-2.0-flash-exp:generateContent?key={api_key}" ) payload = { "contents": [{"parts": [{"text": prompt}]}], "generationConfig": {"responseModalities": ["TEXT", "IMAGE"]}, } response = requests.post(url, json=payload, timeout=60) ``` The command-line option is registered as follows: ```python parser.add_argument("--api-key", help="Gemini API key") ``` The documentation explicitly demonstrates passing the credential through that option: ```bash python scripts/generate_memorable_image.py \ --prompt "your image description" \ --output path/to/output.png \ --threshold 0.75 \ --max-attempts 3 \ --api-key YOUR_KEY \ --verbose ``` ### Technical Analysis The Skill accepts the Gemini API key as a command-line argument. Command-line arguments can be exposed through shell history, process inspection facilities, job-control systems, diagnostic tools, audit logs, and automation logs. The key is then concatenated into the request URL as a query param ...[truncated 1879 chars]- Remediation
View remediation
