T09 · Insecure Skill Coding Practices
- Location
SKILL.md:28- Finding
Access Token Permitted in URL Query Strings
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 28-38
Vulnerability Type: Credential exposure through query-string authentication
Risk Level: MediumVulnerable Code
text ## Authentication ### Method Use access token in query or header: Authorization: Bearer <ACCESS_TOKEN> or ?access_token=<ACCESS_TOKEN>Technical Analysis
The Skill explicitly permits a Meta access token to be placed in a URL query parameter. Although transmitting the token to the declared Meta Graph API is necessary for the Skill's functionality, query strings are an unnecessarily exposed authentication channel.
Complete URLs are commonly captured by reverse proxies, API gateways, HTTP clients, monitoring platforms, debugging output, shell history, and application logs. Anyone with access to such records could recover the token. This also conflicts with the Skill's later instruction to never expose access tokens.
The token's effective capabilities depend on its assigned permissions. The documented permissions include
ads_readandads_management, which can provide access to confidential advertising data and permit campaign modifications.Attack Path
- The agent follows the documented query-string authentication option.
- It constructs a request containing
?access_token=<ACCESS_TOKEN>. - An intermediary, HTTP client, monitoring service, or logging component records the complete URL.
- A party with access to those records extracts the reusable token.
- The party submits requests to the Meta Marketing API using the stolen token.
- Subject to the token's scope, account access, and expiration, the party reads advertising information or modifies campaigns.
Impact Assessment
A compromised token may expose campaign names, identifiers, performance metrics, spending information, creatives, and other advertising-account data. If the token has
ads_management, an attack ...[truncated 183 chars]- Remediation
View remediation
Remediation Suggestions
- Remove support for
access_tokenquery parameters. - Require
Authorization: Bearer <ACCESS_TOKEN>for every authenticated request. - Explicitly prohibit credentials in URLs, pagination links, error messages, and diagnostic output.
- Configure HTTP clients, proxies, and monitoring systems to redact the
Authorizationheader. - Use short-lived or appropriately rotated tokens where operationally possible.
- Restrict each token to the minimum required permissions; use
ads_readalone for read-only workflows. - Revoke and rotate any token suspected of appearing in URL or request logs.
- Remove support for
