T09 · Insecure Skill Coding Practices
- Location
assets/blueprints/landing-zone-setup/04-log/tos_activate.py:296- Finding
Cloud Credentials Exposed Through Process Command-Line Arguments
- Content
View full analysis
/cmdline` or process-listing tools. - Shell history when the helper is invoked manually. - Terraform `local-exec` diagnostics and command logging. - CI/CD job logs, endpoint monitoring, audit collectors, or crash reports. - Process telemetry collected by other software on the execution host. The helper uses these credentials to generate signed HTTPS requests. The outbound destination is restricted by `KNOWN_HOSTS` and `resolve_host()` to the official endpoint `tos.cn-beijing.volcengineapi.com`, so the network request itself is necessary for the declared centralized-logging functionality and is not evidence of arbitrary exfiltration. The weakness is the local credential transport mechanism. This implementation also conflicts with the project's documented security rule in `references/account-factory/guidebook.md`, which requires base credentials to remain off the command line. ### Attack Path 1. The centralized-logging phase assumes a role in the log archive account and obtains temporary cl ...[truncated 1341 chars]- Remediation
View remediation
