T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_samples.py:571- Finding
CryptoPanic API Token Exposed Through Command-Line Arguments and URL Query Strings
- Content
View full analysis
JSONList: url = ( "https://cryptopanic.com/api/developer/v2/posts/?" f"auth_token={token}&public=true¤cies={base_symbol}&kind={kind}" ) try: resp = requests.get(url, timeout=10) ``` Related documentation explicitly encourages the command-line option in `references/data_sources.md:13` and describes the token-bearing URL at `references/data_sources.md:40-41`. ### Technical Analysis The `--token` option allows a credential to be supplied directly in the process command line. Depending on the operating system and runtime environment, command-line arguments may be exposed through: - Shell history files. - Process inspection utilities. - Process accounting or endpoint monitoring. - CI/CD job logs. - Wrapper scripts and orchestration metadata. The token is then interpolated into the request URL as the `auth_token` query parameter. Although HTTPS encrypts the request in transit, query strings can still be captured by local HTTP debugging, application-performance monitoring, proxy telemetry, exception instrumentation, or server-side access logs. The request is sent only to the declared CryptoPanic HT ...[truncated 1215 chars]- Remediation
View remediation
