T09 · Insecure Skill Coding Practices
- Location
journey.sh:104- Finding
ResRobot API Key Exposed Through the curl Process Command Line in Journey Search
- Content
View full analysis
/cmdline` or process-monitoring utilities. Access depends on the host's user isolation, `/proc` configuration, and tracing restrictions, but a sufficiently privileged local process may capture the credential. Query-string credentials may also be exposed if command execution, process telemetry, or diagnostic data is recorded by surrounding automation. ### Attack Path 1. A victim configures a valid `RESROBOT_API_KEY`. 2. The victim invokes `journey.sh`. 3. The shell expands `${PARAMS}`, including `accessId=${API_KEY}`, into the URL passed to `curl`. 4. While `curl` is active, a local attacker or monitoring process with sufficient process-inspection privileges reads the command line. 5. The attacker extracts the API key from the `accessId` query parameter. 6. The attacker reuses the credential to make unauthorized ResRobot API requests. ### Impact Assessment The issue does not directly grant shell execution or elevated operating-system privileges. It can disclose the victim's Trafiklab/ResRobot API credential to a local actor capable of inspecting the process. ...[truncated 314 chars]- Remediation
View remediation
