T09 · Insecure Skill Coding Practices
- Location
scripts/product-search.js:14- Finding
Authentication Token Exposed Through Command-Line Arguments and Sent to a Hard-Coded Test Endpoint
- Content
View full analysis
--token= ``` ```markdown - `--token=`: **(Required)** Your authentication token for the Codrop API. ``` The script reads that argument and sends it as an HTTP header to a hard-coded testing hostname: ```js const keyword = args.keyword; const token = args.token; ``` ```js const options = { hostname: 'test-codrop.cargosoon.online', path: '/api/shipping/Goods/ProductSearchKeywordQuery', method: 'POST', headers: { 'Content-Type': 'application/json', 'Content-Length': Buffer.byteLength(postData), 'token': token } }; ``` ### Technical Analysis Passing credentials through command-line arguments is an insecure secret-handling practice. Depending on the operating system and execution environment, command arguments may be exposed through: - Shell command history. - Process inspection utilities and process metadata. - Monitoring, telemetry, or diagnostic systems that record process invocations. - CI/CD logs, wrapper scripts, or terminal session recordings. The recovered token may remain useful after the process terminates because it is an API credential rather than an ephemeral value generated exclusively for the process. The token is subsequently transmitted over HTTPS to the hard-coded hostname `test-codrop.cargosoon.online`. HTTPS provides transport confidentiality and server authentication when certificate validation succeeds, but it does not prevent prior local disclosure through process arguments. Moreover, `SKILL.md` refers only to the generic “Codrop API” and does not identif ...[truncated 1541 chars]- Remediation
View remediation
