T09 · Insecure Skill Coding Practices
- Location
actionfigure.js:3- Finding
API Token Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
actionfigure.js:3-14,SKILL.md:11-20,README.md:57-63
Vulnerability Type: API credential exposure through process arguments
Risk Level: MediumVulnerable Code
actionfigure.js:3-14:javascript // --- Argument parsing --- const args = process.argv.slice(2); let prompt = null; let size = "portrait"; let tokenFlag = null; let refUuid = null; for (let i = 0; i < args.length; i++) { if (args[i] === "--size" && args[i + 1]) { size = args[++i]; } else if (args[i] === "--token" && args[i + 1]) { tokenFlag = args[++i];SKILL.md:11-20:bash export NETA_TOKEN=your_token_here node <script> "your prompt" --token "$NETA_TOKEN"bash node actionfigure.js "your description here" --token YOUR_TOKENREADME.md:57-63:markdown This skill requires a Neta API token (free trial available at <https://www.neta.art/open/>). Pass it via the `--token` flag: ```bash node <script> "your prompt" --token YOUR_TOKENtext ### Technical Analysis The implementation obtains the API token exclusively from `process.argv`. Command-line arguments are commonly exposed through operating-system process inspection interfaces for at least the lifetime of the process. Depending on the operating system and process isolation settings, another local user or process may be able to inspect the command line and recover the token. The documented example using a literal `YOUR_TOKEN` value also encourages users to type a credential directly into a shell command. In that usage pattern, the command may remain in shell history. Although the Skill metadata declares a `NETA_TOKEN` environment variable, `actionfigure.js` does not read `process.env.NETA_TOKEN`; the environment variable is expanded and passed back into the process argument list by the documented command. The token is subsequently ...[truncated 1364 chars]- Remediation
View remediation
Remediation Suggestions
-
Read the token from
process.env.NETA_TOKENby default:javascript const TOKEN = process.env.NETA_TOKEN || tokenFlag; -
Update all usage examples to avoid putting credentials on the command line:
bash export NETA_TOKEN="your-token" node actionfigure.js "your prompt" -
Prefer credential injection through a secrets manager in CI and hosted environments.
-
If
--tokenis retained for compatibility, explicitly warn that it may expose the token through process listings and shell history. -
Optionally support reading the token from a protected file or standard input without echo.
-
Ensure errors and diagnostic logs never print the request headers or token.
-
Recommend rotating the token if it has previously been entered literally into shell history or exposed in process logs.
-
