T09 · Insecure Skill Coding Practices
- Location
SKILL.md:252- Finding
API Key Exposed Through URL Query Parameters and Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 252–256
Vulnerability Type: API credential exposure through insecure configuration
Risk Level: MediumVulnerable Code
markdown | **VS Code / Cursor** | Add to MCP config: `{"servers":{"linkup":{"url":"https://mcp.linkup.so/mcp?apiKey=YOUR_API_KEY","type":"http"}}}` | | **Claude Code** | `claude mcp add --transport http linkup https://mcp.linkup.so/mcp?apiKey=YOUR_API_KEY` | | **Claude Desktop** | Download [MCPB bundle](https://github.com/LinkupPlatform/linkup-mcp-server/releases/latest/download/linkup-mcp-server.mcpb), double-click to install | Auth format (v2.x): `apiKey=YOUR_API_KEY` in args. Old v1.x `env` format no longer works.Technical Analysis
The Skill directs users to replace
YOUR_API_KEYwith a real Linkup API key embedded in an HTTPS URL query parameter. The Claude Code setup command also places the resulting credential-bearing URL directly in command-line arguments.Although HTTPS protects the URL while it is transmitted over the network, it does not prevent local or intermediary disclosure. A credential in this location may be retained in:
- Shell command history.
- Process command-line metadata visible to other local processes or users, depending on operating-system controls.
- MCP client configuration files.
- Diagnostic reports and application logs.
- Proxy, monitoring, or URL-access logs.
- Screenshots, copied commands, and support bundles.
Sending authentication data to Linkup is necessary for the declared search functionality, and the documented destination is the expected Linkup service rather than an unrelated exfiltration endpoint. However, placing the key in a URL and explicitly requiring it in command arguments exceeds secure minimum credential-handling practices.
Attack Path
- A user replaces
YOUR_API_KEYwith a valid Linkup API key. - The user runs the documented Claude Code command or s ...[truncated 1055 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer an authorization header, protected environment variable, operating-system credential store, or MCP client's native secret-management facility instead of a URL query parameter.
- Do not place credentials directly in command-line arguments, because arguments may be exposed through process inspection and shell history.
- Store secrets separately from ordinary MCP configuration and restrict secret-file permissions to the owning user.
- Ensure clients, proxies, and diagnostics redact the
apiKeyparameter from logs and error messages. - If Linkup currently mandates query-parameter authentication, construct the authenticated URL at runtime from protected secret storage rather than asking users to type or persist the completed URL.
- Clearly warn users about shell-history and configuration-file exposure, and provide platform-specific secure setup examples.
- Rotate any key that may already have appeared in command history, logs, screenshots, or shared configuration.
- Apply account-side key scoping, usage limits, monitoring, and revocation controls to reduce the impact of credential compromise.
