T09 · Insecure Skill Coding Practices
- Location
SKILL.md:112- Finding
API Key Exposure Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 112, 195, and 264
Vulnerability Type: Credential exposure through process arguments and shell history
Risk Level: MediumVulnerable Code
Line 112:
bash dlazy auth set YOUR_API_KEYLine 195 recommends the same command as an authentication option:
bash dlazy auth set YOUR_API_KEYLine 264 repeats the recommendation for persistent configuration:
bash dlazy auth set YOUR_API_KEYTechnical Analysis
The Skill instructs users to provide a dLazy API key directly as a command-line argument. Secrets supplied this way can be exposed through shell-history files, terminal logging, process monitoring, audit systems, support bundles, or process-listing interfaces available to other local users.
Although the document separately states that API keys must not be logged or exposed, this authentication method does not reliably satisfy that requirement. Persistence of the key in the dLazy configuration also depends on the external CLI correctly enforcing restrictive file permissions.
Attack Path
- A user replaces
YOUR_API_KEYwith a valid organization API key and runs the documented command. - The shell records the complete command in its history, or a local monitoring mechanism captures the process arguments.
- Another local user, malicious process, administrator, diagnostic collector, or attacker with access to copied history files retrieves the key.
- The attacker authenticates to the dLazy service using the compromised credential.
- The attacker consumes organization credits or accesses any service capabilities authorized to that key until it is revoked.
Impact Assessment
Exploitation does not directly grant local operating-system privileges. It can grant the attacker the remote service permissions assigned to the exposed key. Potential consequences include unauthorized API use, consumption of paid c ...[truncated 260 chars]
- A user replaces
- Remediation
View remediation
Remediation Suggestions
- Replace command-line secret entry with an interactive, no-echo authentication prompt.
- Where supported, accept the key through standard input or an operating-system credential manager.
- If an environment variable is required, scope it to a single process rather than exporting it for an entire long-lived shell session.
- Explicitly warn users not to place API keys in command arguments, scripts, copied terminal transcripts, or shell-history files.
- Ensure persisted credentials are stored with owner-only permissions and reject configuration files with unsafe permissions.
- Recommend narrowly scoped, short-lived keys where the service supports them.
- Add instructions for immediately rotating a key that may have appeared in shell history or logs.
