T09 · Insecure Skill Coding Practices
- Location
SKILL.md:220- Finding
API Credentials Exposed to an Unbundled External Client Through Command-Line Arguments
- Content
View full analysis
", "query": "search term", "cursor": ""}' \ '{"clientId":"","apiKey":""}' # Browse knowledge-base content node /Users/wdj/.workbuddy/skills/skill_2053082144792322048/ima_api.cjs \ "openapi/wiki/v1/get_knowledge_list" \ '{"knowledge_base_id": "", "cursor": "", "limit": 50}' \ '{"clientId":"","apiKey":""}' ``` ### Technical Analysis The instructions direct the user or Agent to obtain a client identifier and API key from local configuration files and then place those credentials directly into a process argument. On operating systems where process command lines are visible through process-monitoring interfaces, the credentials may be exposed to other local users, monitoring agents, diagnostic utilities, shell history, terminal capture, or automation logs. Passing secrets in an argument also increases the chance that orchestration or error-reporting systems will retain them. The invoked JavaScript client is referenced through the absolute path: ```text /Users/wdj/.workbuddy/skills/skill_2053082144792322048/ima_api.cjs ``` That file is outside the audited project and was not available for inspection. Consequently, the audit cannot verify its network destination, request handling, logging behavior, or treatment of the supplied credentials. The absolute path also creates a local trust boundary: if an attacker can replace or modify that file, the attacker-controlled program will receive the API ...[truncated 1811 chars]- Remediation
View remediation
