T09 · Insecure Skill Coding Practices
- Location
scripts/twitter_api.py:178- Finding
API Key Exposure Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/twitter_api.py:178(unsafe option implementation);SKILL.md:59-60(unsafe usage guidance)
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: MediumVulnerable Code
scripts/twitter_api.py:178:python parser.add_argument("--azt_api_key", default=None, help="API Key(也可通过环境变量 AZT_API_KEY 设置)")SKILL.md:59-60:bash # 付费版(直接传参) python3 scripts/twitter_api.py search --keyword "elon musk" --azt_api_key your_key_hereTechnical Analysis
The Skill accepts a paid-service API key as a command-line argument and explicitly instructs users to place the secret directly in a shell command. Secrets supplied this way may be exposed through:
- Shell history files.
- Process listings and process-monitoring utilities.
- Endpoint detection, command telemetry, or operating-system audit logs.
- Terminal session logging and copied command transcripts.
- Automation logs that record complete command lines.
The script subsequently transmits the key over HTTPS only to the declared third-party API endpoint. That network transmission is required for authenticated use of the declared service and does not, by itself, exceed the Skill's functional privileges. The vulnerability is the optional command-line secret-input channel, not the disclosed HTTPS request.
The documented example places the global option after the subcommand and may not be accepted by the current
argparseconfiguration. Nevertheless, the implementation exposes a functioning command-line credential channel when the global option is placed in an accepted position, such as before the subcommand.Attack Path
-
A user invokes the script with a real API key in the command line, for example:
bash python3 scripts/twitter_api.py --azt_api_key REAL_SECRET search --keyword "OpenAI" -
The complete command is retained in she ...[truncated 1359 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
--azt_api_keycommand-line option so credentials cannot be supplied through process arguments. - Remove the inline-key command example from
SKILL.md. - Retain
AZT_API_KEYenvironment-variable support for non-interactive operation, while documenting that secrets should be injected through a protected runtime secret manager rather than placed in shell startup files or committed configuration. - For interactive use, support a non-echoing prompt with
getpass.getpass()when no managed credential is available. - In CI/CD and hosted Agent environments, obtain the key from the platform's credential store and ensure it is masked in logs.
- Never print the key or include it in exception messages, request diagnostics, or raw debugging output.
- Rotate any production key that has previously been supplied on a command line, and remove affected commands from shell histories and retained logs where feasible.
- Apply service-side controls where available, including narrow API scopes, quota limits, expiration, usage monitoring, and rapid revocation.
- Remove the
