T09 · Insecure Skill Coding Practices
- Location
scripts/activity.sh:4- Finding
Tautulli API Key Exposed in Request URLs and Potentially Plaintext HTTP Traffic
- Content
View full analysis
``` ``` `README.md:28-38`: ```markdown Set environment variables in your OpenClaw config (`~/.openclaw/openclaw.json`): ```json { "env": { "vars": { "TAUTULLI_URL": "http://192.168.1.100:8181", "TAUTULLI_API_KEY": "your-api-key-here" } } } ``` ``` ### Technical Analysis All six scripts place `TAUTULLI_API_KEY` directly in the request query string. Query-string credentials can be exposed through process inspection while `curl` is running, rever ...[truncated 2387 chars]- Remediation
View remediation
&2 exit 1 ;; esac ``` 2. **Avoid query-string credentials where supported** - If the deployed Tautulli API version supports authentication through a request header or POST body, use that mechanism instead of `apikey` in the URL. - If query-string authentication is unavoidable, clearly document that complete URLs must not be logged and that the key may be visible in process arguments. 3. **Harden `curl` invocation** - Use options that report HTTP failures and constrain permitted protocols, such as: ```bash curl --silent --show-error --fail --proto '=https' \ "$TAUTULLI_URL/api/v2?apikey=$TAUTULLI_API_KEY&cmd=get_activity" ``` - Where loopback HTTP must remain supported, select protocol restrictions based on a separately validated URL rather than allowing arbitrary schemes. 4. **Reduce credential exposure** - Redact the `apikey` parameter from reverse-proxy, Tautulli, monitoring, and diagnostic logs. - Prevent untrusted users from reading application configuration containing `TAUTULLI_API_KEY`. - Use a restricted API credential if Tautulli supports permission scoping. - Rotate the key immediately if it may already have appeared in logs or traversed an untrusted plaintext network. 5. **Improve documentation** - State that viewing activity and history are sensitive information. - Recommend trusted certificates and HTTPS for all non-loopback deployments. - Explain the residual logging risk if Tautulli requires query-string API authentication. ]]>
