T09 · Insecure Skill Coding Practices
Warning
- Location
SKILL.md:76- Finding
API Token Exposure Through Console Output and URL Query Parameters
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 } ``` 2. Use an authorization header instead of a query parameter if the EODHD API supports secure header-based authentication. 3. If query-parameter authentication is required by the service: - Do not print the expanded request URL. - Disable shell tracing before executing the request. - Ensure Agent and tool logs redact `api_token` parameter values. - Prevent monitoring and proxy systems from retaining full query strings. - Restrict process inspection and execution-log access to trusted principals. - Avoid verbose `curl` options that may expose request details. 4. Configure automated secret redaction for patterns such as: ```text api_token=[^&[:space:]]+ EODHD_API_TOKEN ``` 5. Use a narrowly scoped token where supported, enforce usage limits, monitor the usage endpoint for anomalies, and rotate the token immediately if it has appeared in logs or transcripts. 6. Add explicit Skill guidance stating that credentials must never be displayed, returned to users, included in diagnostic output, or persisted in conversation history. ]]>
