T09 · Insecure Skill Coding Practices
- Location
scripts/xpeng_eu_daily.js:256- Finding
Account Password Exposed Through Agent Conversation and Process Arguments
- Content
View full analysis
--password `. 4. After successful login, the session is automatically saved in `.eu-session.json`. ``` The script directly reads these secrets from its process arguments at `scripts/xpeng_eu_daily.js:256-273`: ```javascript function parseArgs() { const args = process.argv.slice(2); let year = String(new Date().getFullYear()); let email = null; let password = null; let report = false; for (let i = 0; i < args.length; i++) { if (args[i] === '--email' && i + 1 < args.length) { email = args[++i]; } else if (args[i] === '--password' && i + 1 < args.length) { password = args[++i]; } else if (args[i] === '--report') { report = true; } else if (!args[i].startsWith('--')) { year = args[i]; } } return { year: parseInt(year, 10), email, password, report }; } ``` ### Technical Analysis The workflow requires the user to disclose a reusable account password in the agent conversation. It then transports that password to the Node.js process through `process.argv`. Secrets passed through these channels may be exposed by: - Agent conversation history and orchestration logs. - Tool-call and execution telemetry. - Shell history if a comman ...[truncated 1822 chars]- Remediation
View remediation
