T09 · Insecure Skill Coding Practices
- Location
gkeep.py:457- Finding
Authentication Secrets Exposed Through Command-Line Arguments
- Content
View full analysis
gkeep auth-master ``` ### Technical Analysis Both authentication flows require sensitive tokens to be supplied as positional command-line arguments. Command-line secrets may be recorded in shell history, terminal session logs, process-accounting systems, endpoint monitoring tools, or diagnostic bundles. Depending on the operating system and process visibility configuration, other local users or processes may also be able to inspect the argument vector while the command is running. This is particularly sensitive for `auth-master`, because the project documentation states that the master token does not expire and grants full access to the associated account. Although the application subsequently stores the token in a file with mode `0600`, those file permissions do not protect the original token while it is present in the command invocation. ### Attack Path 1. A user follows the documented setup instructions and executes `gkeep auth-master user@example.com ` ...[truncated 1182 chars]- Remediation
View remediation
