T09 · Insecure Skill Coding Practices
- Location
SKILL.md:39- Finding
API Key Exposure Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 39–42
Vulnerability Type: Sensitive credential exposure through process arguments and shell history
Risk Level: MediumVulnerable Code
bash or pass it in the command: ```bash python3 {baseDir}/scripts/seedream.py --api-key "your-api-key" ...text ### Technical Analysis The documentation recommends supplying the `ARK_API_KEY` directly through the `--api-key` command-line option. Secrets passed as command-line arguments can be recorded in shell history, terminal-session logs, process-monitoring systems, diagnostic reports, and automation logs. Depending on operating-system configuration, process arguments may also be visible to other local users or processes while the command is running. Although the referenced `scripts/seedream.py` implementation is absent and its internal credential handling cannot be verified, the documented invocation itself creates a credential-exposure risk. ### Attack Path 1. A user follows the documented example and supplies a valid API key using `--api-key`. 2. The complete command is retained in shell history, captured by logging or monitoring software, or temporarily exposed through process metadata. 3. A local attacker, compromised process, support operator, or user with access to collected logs retrieves the key. 4. The attacker reuses the credential against services accessible under the key. ### Impact Assessment Successful exploitation exposes the privileges associated with the compromised API key. An attacker could consume the victim's service quota, incur charges, invoke authorized API operations, or access other resources available to that credential. The exact scope depends on the server-side permissions assigned to the key; no evidence establishes broader local-system privileges.- Remediation
View remediation
Remediation Suggestions
- Remove the command-line API-key example and discourage passing secrets in process arguments.
- Require the existing
ARK_API_KEYenvironment variable or use a credential file with restrictive filesystem permissions. - If command-line compatibility must be retained, deprecate
--api-key, emit a warning, and ensure the value is never written to logs or error output. - Prefer an operating-system secret store or managed credential provider for long-lived credentials.
- Document key rotation and revocation procedures for users who may previously have exposed keys through command history.
- Recommend short-lived, least-privilege credentials and ensure generated keys are scoped only to required Seedream operations.
