T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_inventory.py:135- Finding
API Key Exposure Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/fetch_inventory.py:135
Related Documentation:SKILL.md:29
Vulnerability Type: API key disclosure through process arguments and shell history
Risk Level: MediumVulnerable Code
python parser.add_argument("--api-key", default=os.environ.get("ROCOM_API_KEY") or DEFAULT_API_KEY)The documented usage explicitly encourages this insecure input method:
bash python3 skills/rocom-merchant-inventory/scripts/fetch_inventory.py --api-key 你的key --format json --prettyTechnical Analysis
The script permits an API key to be supplied directly through the
--api-keycommand-line option. Command-line arguments are not an appropriate secret transport mechanism because they may be exposed through:- Shell history files.
- Process inspection utilities and process metadata.
- Endpoint monitoring and audit systems.
- Terminal session logging.
- CI/CD job logs or wrapper scripts that record executed commands.
The script also supports the
ROCOM_API_KEYenvironment variable, which avoids placing the key directly in command history, but the unsafe command-line mechanism remains enabled and is explicitly demonstrated in the documentation.The subsequent transmission at
scripts/fetch_inventory.py:92-93is not independently considered malicious:python def fetch(api_key: str): resp = requests.get(API_URL, headers={"X-API-Key": api_key}, timeout=30)The key is sent over HTTPS, in the documented
X-API-Keyheader, to the fixed API endpoint declared by the skill. Authentication is necessary for the declared inventory-retrieval functionality, and no evidence of transmission to unrelated destinations was found.Attack Path
- A user follows the documented example and invokes the script with
--api-key. - The plaintext API key becomes part of the command line.
- The command is retained in shell history, captured by process monitoring, recorded in job logs, or observed thr ...[truncated 932 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
--api-keyargument so secrets cannot be supplied through process arguments. - Accept the credential through
ROCOM_API_KEYor a protected credential store. - If interactive use is required, use
getpass.getpass()so the key is not echoed or stored in shell history. - Remove the command-line key example from
SKILL.mdand document only safer credential-loading methods. - Advise users to restrict access to any configuration file containing the key and to avoid logging environment contents.
- Rotate any key that may previously have been entered through command-line arguments.
- Where supported by the API provider, use narrowly scoped, short-lived, and revocable credentials.
A hardened interface could reject command-line secret input and require the environment variable:
python api_key = os.environ.get("ROCOM_API_KEY") if not api_key: print( json.dumps( { "ok": False, "error": "ROCOM_API_KEY is required.", } ), file=sys.stderr, ) sys.exit(2)- Remove the
