T09 · Insecure Skill Coding Practices
- Location
README.md:34- Finding
Credentials Are Requested in Chat and Embedded in Command-Line Arguments
- Content
View full analysis
"Configure Postzee with my API key: pk_your_key_here" Get your API key at [dashboard.postzee.app/settings](https://dashboard.postzee.app/settings). ``` `SKILL.md:15-21`: ```markdown ## Setup (First Time Only) If the MCP server is not configured yet, help the user set it up: 1. **Ask for the MCP URL**: "Copy your MCP URL from https://dashboard.postzee.app/settings → tab 'API Pública' → section 'MCP (Model Context Protocol)'. It looks like: `https://api.postzee.app/mcp/.../sse`" 2. **Configure MCP**: - **Claude Code**: Run `claude mcp add --transport sse postzee ` (paste the full URL) ``` ### Technical Analysis The documented setup procedure instructs users to submit a Postzee API key directly in an agent conversation. Conversations may be retained in local histories, remote service logs, debugging traces, telemetry, transcripts, or support exports. Consequently, the API key can persist outside a purpose-built secret store. The skill also instructs users to place the complete credential-bearing MCP URL directly in a command-line argument. Depending on the operating system and invocation environment, command arguments may be exposed through: - Shell command history - Process-listing utilities - Process-monitoring or endpoint-management software - Agent execution logs and debugging traces - Terminal session recording - CI/CD logs if the setup is automated An MCP URL containing a bearer token or equivalent unguessable credential must be treated as a secret. Supplying it verbatim through an agent conversation or command argument unnecessarily expands the number of systems that can retain or observe it. No hardcoded pr ...[truncated 1815 chars]- Remediation
View remediation
