T09 · Insecure Skill Coding Practices
- Location
SKILL.md:1196- Finding
Bearer API Key May Be Exposed Through Verbose curl Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:1196-1199
Vulnerability Type: Sensitive credential exposure through verbose diagnostic output
Risk Level: MediumVulnerable Code
bash curl -X POST https://monet.vision/api/v1/files \ -H "Authorization: Bearer $MONET_API_KEY" \ -F "file=@/path/to/your/file.mp4" \ -vTechnical Analysis
The documented file-upload command combines an
Authorizationheader containingMONET_API_KEYwith curl's verbose (-v) diagnostic mode. Verbose diagnostics can disclose sensitive request details, potentially including authentication headers, depending on the curl version and diagnostic environment.Because verbose output is written to standard error, the credential may be captured by CI/CD logs, shell-session recordings, AI-agent transcripts, support bundles, or redirected diagnostic files. Although transmitting the key to
https://monet.visionis necessary for the declared hosted API functionality, exposing it through local diagnostics is not necessary and exceeds the minimum disclosure required.The API key itself is loaded from an environment variable rather than hardcoded, which is appropriate. The vulnerability arises from unsafe diagnostic handling rather than from the authentication mechanism.
Attack Path
- A user or automation system copies the documented upload command.
- The command runs with a valid
MONET_API_KEYand verbose mode enabled. - Request diagnostics are displayed or captured by a terminal recorder, CI job, agent transcript, support log, or stderr redirection.
- An unauthorized party obtains access to the retained diagnostic output.
- If the authorization value was included in that output, the party extracts the bearer token.
- The party reuses the token against the Monet API until the credential expires or is revoked.
Impact Assessment
Successful exploitation could grant the attacker the Monet API priv ...[truncated 560 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
-vfrom the documented upload command:bash curl -X POST https://monet.vision/api/v1/files \ -H "Authorization: Bearer $MONET_API_KEY" \ -F "file=@/path/to/your/file.mp4" - If diagnostics are required, use a controlled troubleshooting process that explicitly redacts
Authorization, cookies, signed URLs, and other secrets before logs are retained or shared. - Prevent command output containing credentials from being stored in CI logs, agent transcripts, shell history, or support artifacts.
- Add documentation warning users not to enable verbose tracing while authenticated unless sensitive fields are safely redacted.
- Rotate
MONET_API_KEYimmediately if verbose output from previous executions may have been recorded or disclosed. - Apply least privilege, usage limits, expiration, and regular rotation to API keys where supported.
- Remove
