T09 · Insecure Skill Coding Practices
- Location
scripts/notion_publisher.py:72- Finding
Insecure Storage and Command-Line Handling of the Notion Integration Token
- Content
View full analysis
None: env_path = CONFIG_DIR / ".env" if not env_path.exists(): return for raw_line in env_path.read_text(encoding="utf-8").splitlines(): line = raw_line.strip() if not line or line.startswith("#") or "=" not in line: continue key, value = line.split("=", 1) key = key.strip() value = value.strip().strip('"').strip("'") os.environ.setdefault(key, value) ``` The token is then retrieved from either a command-line argument or the environment: ```python token = args.token or os.environ.get("NOTION_TOKEN") ``` The global command-line option permits the secret to be passed directly in process arguments: ```python parser.add_argument("--token", help="Notion integration token. Defaults to NOTION_TOKEN.") ``` ### Technical Analysis The application supports a plaintext `.env` file for storing a Notion integration token, but neither the documentation nor the ...[truncated 3371 chars]- Remediation
View remediation
