T09 · Insecure Skill Coding Practices
- Location
SKILL.md:45- Finding
Personally Identifiable Information Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 45–48
Vulnerability Type: Plaintext sensitive data in process arguments
Risk Level: Mediumbash curl -X POST "https://asapps.suning.com/asapps/mcp/serviceReserveNew" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "phone=13812345678" \ --data-urlencode "serviceDescription=[fault description]"The final parameter above represents the non-English example fault description in the source while preserving its security-relevant placement as a command-line argument.
Technical Analysis
The documented command places a user's phone number and appliance fault description directly in
curlcommand-line arguments. Although HTTPS protects the request in transit and POST keeps these values out of the URL query string, neither control prevents local disclosure through process inspection, command-execution auditing, terminal capture, shell history, or orchestration logs.Any implementation that substitutes real user information into this command may expose that information for the lifetime of the process or retain it in local records. The document's claim that POST avoids sensitive-data logging is incomplete because POST only changes where the HTTP data is placed; it does not protect command-line arguments or prevent the receiving service from logging request bodies.
Attack Path
- A user provides a phone number and fault description to the Skill.
- The Agent confirms the information and substitutes it into the documented
curlcommand. - The command executes with both values present in its process argument vector.
- A local user, process monitor, command-auditing service, terminal recorder, shell-history mechanism, or execution platform captures the arguments.
- The observer retrieves the user's phone number and potentially sensitive household-service information.
Exploitation requires access to local process metadata or re ...[truncated 713 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not place phone numbers, fault descriptions, or other personal data directly in command-line arguments.
- Submit the encoded request body through standard input where supported, or use an application HTTP client that keeps sensitive values in memory rather than in the process argument vector.
- If temporary files are unavoidable, create them with owner-only permissions, use unpredictable filenames, prevent symbolic-link attacks, and delete them immediately after use.
- Disable or avoid shell-history recording for commands handling personal information.
- Redact phone numbers and service descriptions from Agent traces, terminal output, process-execution logs, error messages, and observability systems.
- Validate phone-number format and constrain the maximum length of the fault description before submission.
- Continue requiring explicit user confirmation before transmission.
- Update the security documentation to clarify that HTTPS and POST protect transport and URL placement, but do not prevent local process metadata or server-side request-body logging.
