T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_hot_rise_list.py:21- Finding
API Key Exposure Through Command-Line Arguments
- Content
View full analysis
str: """优先使用参数传入的 key,否则读取环境变量 AZT_API_KEY""" key = arg_key or os.environ.get("AZT_API_KEY", "").strip() if not key: print( "❌ 未检测到 API Key。\n" " 请前往 https://devtool.uk/wiki 购买或查看使用说明,\n" " 然后通过以下任一方式提供 Key:\n" " 1. 设置环境变量:export AZT_API_KEY=\"your_key\"\n" " 2. 传入参数:python3 fetch_hot_rise_list.py --azt_api_key your_key", file=sys.stderr, ) sys.exit(1) return key ``` The corresponding argument is registered as follows: ```python parser.add_argument("--azt_api_key", default=None, help="API Key(也可通过环境变量 AZT_API_KEY 设置)") ``` ### Technical Analysis The script accepts the API credential through the `--azt_api_key` command-line option and explicitly recommends this method in its error message. Secrets supplied as command-line arguments can be exposed through: - Shell history files. - Process listings and process-monitoring utilities while the script is running. - Terminal logging and command auditing systems. - Wrapper scripts, job schedulers, or diagnostic tools that record complete command lines. The implementation does not print the resolved key, and the outbound request uses HTTPS. However, those controls do not prevent local disclosure before the request is made. Accepting the key through an environment variable is safer than a command-line argument, but the current documentation and implementation continue to promote both methods. The key is sent only to the declared service endpoint and is necessary for the advertised API functionality. No unrelated environment variables or loc ...[truncated 1555 chars]- Remediation
View remediation
