T09 · Insecure Skill Coding Practices
- Location
scripts/send.py:98- Finding
SMTP Password Exposed Through Command-Line Arguments
- Content
View full analysis
" \ --rate-limit 15 \ --out-log out/send_results.csv ``` ### Technical Analysis Accepting an SMTP password through `--smtp-pass` exposes the secret as part of the process command line. Depending on the operating system and execution environment, command-line arguments may be available through: - Process inspection tools such as `ps` or `/proc//cmdline` - Shell history - CI/CD and automation logs - Terminal-session recording - Process monitoring and endpoint-management systems - Parent-process telemetry The exposure window may be prolonged because the script sleeps between recipient attempts to implement rate limiting. Although SMTP authentication is necessary for the declared functionality, exposing the password through a command-line argument is not necessary and exceeds secure credential-handling requirements. No hardcoded SMTP credential was found, and the password is not intentionally written to the result log. ### Attack Path 1. An operator foll ...[truncated 1329 chars]- Remediation
View remediation
