T09 · Insecure Skill Coding Practices
- Location
scripts/submit_input.py:18- Finding
Sensitive Human Input and 2FA Codes Exposed Through Command-Line Arguments
- Content
View full analysis
"the user's answer" ``` ``` `EXAMPLES.md:87-98`: ```markdown If you can't supply something the task will need (a 2FA code, a clarification), the task will pause and BrowseAnything will return `status: requires_input` with a `human_input_request` question. Provide it via `submit_input.py`. Example: ```bash ID=$(python3 scripts/create_task.py "Log into my Coinbase and return the BTC balance.") # ... time passes ... python3 scripts/get_task.py "$ID" --field status # -> requires_input python3 scripts/get_task.py "$ID" --field human_input_request # Ask the actual user, not the model: python3 scripts/submit_input.py "$ID" "987654" # 2FA code python3 scripts/get_task.py "$ID" ``` ``` `scripts/submit_input.py:18-22`: ```python p.add_argument("task_id") p.add_argument("input", help="Answer to send. Use '-' to read from stdin.") args = p.parse_args() answer = sys.stdin.read().strip() if args.input == "-" else args.input ``` ### Technical Analysis The script accepts sensitive human responses directly as a positional command-line argument. The documentation explicitly demonstrates this mechanism with a Coinbase 2FA code. Command-line secrets can be exposed through: - Shell history files and history synchronization services. - Process inspection utilities while the command is running. - Endpoint monitoring, terminal recording, audit logging, ...[truncated 1969 chars]- Remediation
View remediation
