T09 · Insecure Skill Coding Practices
- Location
SKILL.md:15- Finding
Authentication Secrets Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15–20
Vulnerability Type: Authentication credential exposure through process arguments
Risk Level: MediumVulnerable Code:
sh 1) Authenticate - Token: - `fizzy-cli auth login --token $FIZZY_TOKEN` - Magic link: - `fizzy-cli auth login --email user@example.com` - If non-interactive, pass `--code ABC123`.Technical Analysis
The documented commands pass an API token or one-time authentication code as command-line arguments. The shell expands
$FIZZY_TOKENbefore launchingfizzy-cli, placing the resulting secret in the process argument vector. Depending on operating-system permissions and monitoring configuration, command arguments may be visible through process-inspection utilities, audit systems, telemetry agents, debugging tools, or command-execution wrappers.The magic-link code supplied through
--codeis exposed through the same mechanism. Although such a code may be short-lived, disclosure before expiration can permit unauthorized authentication.Attack Path
- A legitimate user follows the documented authentication procedure and invokes
fizzy-cliwith a token or magic-link code. - The shell expands the environment variable or literal code into the child process's argument vector.
- A local user, monitoring agent, process collector, audit service, or execution wrapper with sufficient visibility records or inspects those arguments.
- The observer extracts the token or still-valid one-time code.
- The exposed credential is replayed against Fizzy to authenticate as the affected user.
- The attacker can perform operations permitted by that credential until it expires or is revoked.
Impact Assessment
Successful exploitation may provide access to the affected Fizzy account and its authorized resources. The resulting scope depends on the privileges associated with the exposed token or account and may in ...[truncated 282 chars]
- A legitimate user follows the documented authentication procedure and invokes
- Remediation
View remediation
Remediation Suggestions
- Add a protected standard-input option such as
fizzy-cli auth login --token-stdin, and document it as the preferred non-interactive authentication method. - For interactive authentication, read tokens and one-time codes using a hidden prompt that disables terminal echo.
- If the current CLI cannot accept secrets securely, update it before recommending token-based automation.
- Avoid supplying tokens, passwords, and one-time authentication codes as command-line arguments.
- Ensure authentication secrets are redacted from application logs, shell tracing, audit output, telemetry, and error messages.
- Store long-lived tokens in a dedicated secret manager or credential store with least-privilege permissions and rotate any credential suspected of exposure.
- Use short-lived, narrowly scoped credentials where supported.
- Add a protected standard-input option such as
