T09 · Insecure Skill Coding Practices
- Location
scripts/generate_auth_token.py:26- Finding
Reversible API Credentials Exposed Through Command-Line Arguments and Standard Output
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate_auth_token.py:26-29, 31-38
Vulnerability Type: Credential exposure through reversible encoding and insecure output
Risk Level: HighVulnerable Code
python credentials = f"{app_key}:{app_secret}" access_token = base64.b64encode(credentials.encode()).decode() return access_token if __name__ == "__main__": if len(sys.argv) != 3: print("Usage: python generate_auth_token.py <app_key> <app_secret>") sys.exit(1) app_key = sys.argv[1] app_secret = sys.argv[2] token = generate_access_token(app_key, app_secret) print(f"Access Token: {token}") print(f"\nUse in Authorization header as: Basic {token}")The vulnerable execution pattern is explicitly documented in
SKILL.md:37-41:bash python scripts/generate_auth_token.py YOUR_APP_KEY YOUR_APP_SECRETTechnical Analysis
HTTP Basic authentication uses Base64 as a transport encoding, not as encryption. The generated token can be decoded directly to recover the original
app_key:app_secretvalue.The helper prints this reversible credential representation to standard output. In an AI Agent context, standard output may be returned to the caller or retained in execution transcripts and logs. The documented invocation also passes the application secret through a command-line argument, which may expose it through shell history, process inspection, command auditing, or orchestration logs.
Although constructing a Basic Authorization header is necessary for the declared API functionality, exposing that token through a standalone helper is not necessary. The main client already generates and applies the header internally.
Attack Path
- A user or Agent follows the command documented in
SKILL.md. - The application key and secret are supplied as process arguments.
- The helper concatenates the credentials and Base6 ...[truncated 1038 chars]
- A user or Agent follows the command documented in
- Remediation
View remediation
Remediation Suggestions
- Remove the helper's token-printing behavior and delete the documented command that encourages users to expose credentials.
- Keep Basic token construction internal to the API client and never log or return authentication headers to Agent-visible output.
- Do not accept secrets through command-line arguments. Use a secret manager, protected environment injection, or interactive input through
getpass.getpass(). - If a diagnostic helper must remain, make it perform a connectivity check without displaying the token or secret.
- Add centralized redaction for
Authorization,app_secret, and Base64-encoded credential values in application, Agent, CI, and HTTP-debug logs. - Update
SKILL.mdto recommend secure secret injection and warn that Basic tokens are equivalent to the underlying credentials. - Rotate any credentials that have already been processed by this helper in logged or Agent-mediated environments.
- Add automated tests that capture stdout and assert that neither raw credentials nor their Base64 representation is emitted.
