T09 · Insecure Skill Coding Practices
- Location
tarotcardartgenerator.js:10- Finding
API Token Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
tarotcardartgenerator.js:10-11; documented usage inSKILL.md:17-19andREADME.md:23-27
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: MediumVulnerable Code
javascript if (args[i] === "--token" && i + 1 < args.length) { tokenFlag = args[++i]; }The documentation explicitly instructs users to provide the credential on the command line:
bash node tarotcardartgenerator.js "your description here" --token YOUR_TOKENTechnical Analysis
The program accepts the Neta API token exclusively through the
--tokencommand-line option. Command-line arguments are not an appropriate secret-transport mechanism because they may be exposed through:- Shell history files.
- Process inspection utilities while the process is running.
- Process-monitoring and endpoint-management software.
- CI/CD command logs and diagnostic output.
- Terminal session recording or copied command transcripts.
The captured value is later assigned to the
x-tokenHTTP request header. The token is not intentionally printed by the application, but accepting it throughprocess.argvexposes it before the request is made.Attack Path
- A user follows the documented usage instructions and runs the generator with
--token YOUR_TOKEN. - The shell records the complete command in its history, or a process-monitoring mechanism captures the process arguments.
- An attacker with access to the user's shell history, process metadata, CI logs, or terminal records extracts the token.
- The attacker submits requests to the Neta API using the stolen
x-tokencredential. - The attacker retains access until the token expires or is revoked.
This attack requires local access, access to collected operational logs, or another capability that exposes process arguments.
Impact Assessment
Successful exploitation ...[truncated 452 chars]
- Remediation
View remediation
Remediation Suggestions
- Read the token from a protected environment variable, such as
NETA_API_TOKEN, rather than requiring it as a command-line argument. - Optionally support secure interactive input from stdin with terminal echo disabled.
- Remove
--token YOUR_TOKENfrom all usage examples and document secure environment-variable setup instead. - If backward compatibility requires retaining
--token, display a deprecation warning and clearly explain the process-list and shell-history risk. - Ensure errors, debug output, telemetry, and request logging redact the token.
- Recommend immediate token rotation if a token has already appeared in shell history or CI/CD logs.
Example hardened token loading:
javascript const TOKEN = process.env.NETA_API_TOKEN; if (!TOKEN) { console.error("Token required. Set the NETA_API_TOKEN environment variable."); process.exit(1); }Recommended invocation:
bash NETA_API_TOKEN='token-value' node tarotcardartgenerator.js "your description"For shared systems, a protected secret manager or non-echoing stdin input is preferable even to an inline environment-variable assignment.
- Read the token from a protected environment variable, such as
