T09 · Insecure Skill Coding Practices
- Location
SKILL.md:49- Finding
Database Credentials Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 49–51, 64–65, and 68–70
Vulnerability Type: Credentials exposed through process arguments and shell history
Risk Level: MediumVulnerable Code
bash # PostgreSQL psql "postgresql://user:password@host:5432/dbname" -c "\dt" psql "postgresql://user:password@host:5432/dbname" -c "\d table_name" psql "postgresql://user:password@host:5432/dbname" -c "SELECT count(*) FROM table_name;" # MongoDB mongosh "mongodb://user:password@host:27017/dbname" --eval "db.getCollectionNames()" mongosh "mongodb://user:password@host:27017/dbname" --eval "db.collection_name.countDocuments()" # Redis redis-cli -h host -p 6379 -a password INFO keyspace redis-cli -h host -p 6379 -a password DBSIZE redis-cli -h host -p 6379 -a password KEYS "*"Technical Analysis
The examples encourage users to place database passwords directly in command-line arguments. Real credentials substituted into these commands can be retained in shell history and may be visible through local process-inspection interfaces, diagnostic tools, audit logs, or command telemetry.
This behavior conflicts with the safety rule in
SKILL.mdline 78 that states passwords should not be placed in history. Quoting a connection URI does not prevent the complete argument from being recorded or exposed.Attack Path
- A user replaces the placeholder password with a real database credential.
- The command is recorded in shell history or appears in the process argument list while executing.
- Another local user, monitoring service, support bundle, or telemetry collector obtains the command text.
- The exposed credential is extracted from the URI or password argument.
- The attacker connects to the affected database and performs operations permitted by that database account.
Impact Assessment
Exploitation can disclose PostgreSQL, MongoDB, or Redis credentials. The resulting p ...[truncated 387 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove credential-bearing connection strings and
redis-cli -a passwordfrom command examples. - Use interactive password prompts or database-specific protected credential stores.
- For PostgreSQL, use a properly permissioned password file or other supported secret provider.
- For MySQL, use a protected login path or configuration file rather than a command-line password.
- For Redis, use a protected configuration or secret-loading mechanism instead of
-a. - If environment variables are used, avoid printing them and document that some environments may expose process environments to privileged local users.
- Add an explicit warning that quoting credentials does not keep them out of history or process listings.
- Recommend least-privileged, short-lived database credentials and credential rotation following accidental exposure.
- Remove credential-bearing connection strings and
