T09 · Insecure Skill Coding Practices
- Location
SKILL.md:81- Finding
Notion integration token exposed through command-line arguments and persistent cron configuration
- Content
View full analysis
--database-id 。若有逾期書籍,主動發送到期提醒。" ``` The scripts require or accept the token as a command-line argument: ```python parser.add_argument("--api-key", required=True, help="Notion API Key") parser.add_argument("--database-id", required=True, help="Notion Database ID") ``` ### Technical Analysis Passing a Notion integration token through `--api-key` places the secret in the process argument vector. Depending on the operating-system and monitoring configuration, process arguments may be visible through process inspection, audit logs, crash reports, shell history, job execution logs, or administrative dashboards. The documented cron configuration is more serious because it embeds the token in the persisted `--message` payload. The credential therefore survives the current process and may be repeatedly disclosed whenever the job definition or execution history is inspected. Although recurring overdue checks are part of the declared functionality, persisting the credential inside the job text is not necessary. The README mentions environment variables, but the implementation does not read `NOTION_KEY` or `NOTION_DATABASE_ID` from the environment. Consequently, the documented command examples still expand those values into process arguments. ### Attack Path 1. A user follows ...[truncated 1196 chars]- Remediation
View remediation
