T09 · Insecure Skill Coding Practices
- Location
SKILL.md:62- Finding
API Key Exposure Through Chat and Command-Line Arguments
- Content
View full analysis
dict[str, str]: headers = { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json", } ``` ### Technical Analysis API credentials should not be entered into conversational channels or supplied through process command-line arguments. A key pasted into chat may be retained in conversation history, agent traces, telemetry, backups, or execution logs. When supplied through `--api-key`, it may also be visible in shell history, process listings, command auditing, diagnostic output, or orchestration logs. The credential is legitimately required to authenticate with TokenRouter, but exposing it thr ...[truncated 1948 chars]- Remediation
View remediation
