T09 · Insecure Skill Coding Practices
- Location
scripts/garmin-auth.py:49- Finding
Garmin Password Exposed Through Command-Line Arguments
- Content
View full analysis
") print("Example: python3 garmin-auth.py moritz.vogt@vogges.de MyPassword123") sys.exit(1) email = sys.argv[1] password = sys.argv[2] success = setup_oauth(email, password) ``` The insecure invocation is also explicitly recommended in: ```bash python3 scripts/garmin-auth.py your-email@gmail.com your-password ``` at `README.md:18` and `SKILL.md:25`. ### Technical Analysis The authentication script requires the Garmin password as a command-line argument. Command-line arguments can be exposed through: - Shell history files. - Process inspection utilities while the command is running. - System audit and process-accounting services. - Terminal session recording. - Monitoring and endpoint-security software. - Wrapper scripts or job telemetry. The script only needs the password in memory for the authentication request; making it part of the process command line exceeds that requirement. The example also contains a real-looking email address and password pattern that should not be embedded in usage output. ### Attack Path 1. A user follows the documented authentication command and places the Garmin password directly on the command line. 2. The shell records the command in its history, or another local process reads the active process arguments. 3. An attacker with access to the user’s history, monitoring records, or local process metadata retrieves the plaintext password. 4. The attacker authenticates to Garmin using the stolen credentials. 5. The attacker can access account information and sensitive health, sleep, heart-rate, and activity data available to that Garmin account. ### Impact Assessment This issue can disclose the user’s Gar ...[truncated 359 chars]- Remediation
View remediation
