T09 · Insecure Skill Coding Practices
- Location
scripts/generate_metadata.py:167- Finding
Database Credentials Can Be Exposed Through Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate_metadata.py, lines 167–179
Vulnerability Type: Credential exposure through process arguments
Risk Level: MediumVulnerable Code
python parser.add_argument('--db', '--connection', dest='db', help='数据库连接字符串') parser.add_argument('--db-type', choices=['sqlite', 'mysql', 'postgresql'], help='数据库类型(配合环境变量使用)') parser.add_argument('--output', help='输出文件路径') parser.add_argument('--format', choices=['json', 'markdown'], default='json', help='输出格式') args = parser.parse_args() # 验证表名 if not validate_table_name(args.source): sys.exit(1) conn = None try: if args.db: conn = get_connection(args.db)Technical Analysis
The script accepts a complete database connection URI through the
--dbor--connectioncommand-line option. These URIs commonly contain plaintext usernames and passwords, such as:text mysql://username:password@database.example/appCommand-line arguments can be recorded in shell history, CI/CD logs, orchestration audit records, monitoring systems, and diagnostic output. On some systems, they may also be visible to other local users through process-inspection interfaces while the program is running.
This behavior conflicts with the Skill documentation, which instructs users not to place passwords directly on the command line and recommends environment variables. Database connectivity is necessary for metadata generation, but accepting credentials through process arguments is not necessary because the script already supports environment-based configuration.
Attack Path
- An operator runs the metadata script with a credential-bearing connection URI:
bash python scripts/generate_metadata.py --source users \ --db mysql://admin:secret@example.internal/production - The shell records the command in ...[truncated 871 chars]
- An operator runs the metadata script with a credential-bearing connection URI:
- Remediation
View remediation
Remediation Suggestions
- Remove the
--dband--connectionoptions and require environment variables or a protected credential provider. - If connection URIs must remain supported, reject URIs containing usernames or passwords and permit only non-secret connection parameters.
- Add an interactive password prompt using
getpass.getpass()when interactive authentication is required. - Integrate with an operating-system keyring or secrets-management service for production use.
- Update usage examples so they never demonstrate credential-bearing command-line URIs.
- Require a least-privilege, read-only database account limited to the schemas needed for metadata inspection.
- Ensure exception and diagnostic messages redact usernames, passwords, and complete connection URIs.
- Remove the
