T09 · Insecure Skill Coding Practices
- Location
kpopidolgenerator.js:13- Finding
API Token Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
kpopidolgenerator.js:13-24
Vulnerability Type: API credential exposure through process arguments
Risk Level: MediumVulnerable Code
javascript function parseArgs(argv) { const args = { _: [] }; for (let i = 0; i < argv.length; i++) { const a = argv[i]; if (a === '--size') args.size = argv[++i]; else if (a === '--token') args.token = argv[++i]; else if (a === '--ref') args.ref = argv[++i]; else if (a === '--help' || a === '-h') args.help = true; else args._.push(a); } return args; }The insecure invocation method is also explicitly recommended in
SKILL.md:15-19,SKILL.md:25,README.md:20-24, andREADME.md:66-73:bash node kpopidolgenerator.js "your prompt" --token YOUR_TOKENTechnical Analysis
The Skill requires the Neta API credential to be supplied using the
--tokencommand-line option. Command-line arguments are not a suitable secret-delivery mechanism because they may be exposed through:- Shell command history.
- Process inspection utilities and operating-system process metadata.
- Terminal transcripts and session recordings.
- CI/CD logs and automation diagnostics.
- Monitoring or endpoint-management agents that collect process command lines.
The token is legitimately transmitted over HTTPS to
https://api.talesofai.comas anx-tokenheader for image generation and task polling. That network transmission is necessary for the declared hosted API functionality. The vulnerability is the local handling of the token throughprocess.argv, not the authenticated API request itself.No evidence was found that the token is intentionally transmitted to an unrelated service, persisted by the script, or printed directly by the script.
Attack Path
- A user follows the documented instructions and invokes the Skill with
--token YOUR_TOKEN. - The complet ...[truncated 949 chars]
- Remediation
View remediation
Remediation Suggestions
-
Read the token from a protected environment variable by default:
javascript const TOKEN = process.env.NETA_TOKEN;Document usage without placing the secret in the command line:
bash export NETA_TOKEN="..." node kpopidolgenerator.js "your prompt" -
For interactive use, support reading the token from a masked prompt or standard input without echoing it.
-
If
--tokenmust remain for compatibility, mark it as deprecated and display a warning that command-line secrets may be visible in history and process listings. -
Update
README.md,SKILL.md, and built-in help text so the recommended workflow usesNETA_TOKENor protected standard input. -
Advise affected users to remove previously entered literal tokens from shell histories and rotate credentials that may have appeared in logs.
-
Ensure errors and diagnostic output never include request headers or the token.
-
