T09 · Insecure Skill Coding Practices
- Location
SKILL.md:109- Finding
Sensitive API Token Exposed Through URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 109–115
Vulnerability Type: Sensitive credential exposure through URL query parameters
Risk Level: MediumVulnerable Code Snippet
bash curl "https://facebook-graph.baiz.ai/v21.0/act_123456/campaigns?fields=name,status&access_token=yuri_sk_XXXXX"Technical Analysis
The primary usage example instructs users to supply the sensitive
YURI_TOKENin the URL query string. Although the displayed value is a placeholder rather than a live secret, users following the example will replace it with a real credential.Query-string credentials can be recorded in shell history, browser history, HTTP access logs, reverse-proxy and CDN logs, monitoring systems, error reports, and other telemetry. HTTPS encrypts the URL while it is in transit, but it does not prevent either endpoint or authorized intermediaries from recording the complete request target.
The document itself acknowledges this exposure risk in
SKILL.md, lines 148–150:text Because the token is passed as a query parameter, it may appear in browser history, server access logs, proxy logs, and CDN logs. For POST/PUT requests, prefer passing the token in the request body (as a form field `access_token`) instead of the URL query string.The warning reduces but does not eliminate the vulnerability because the primary copyable example still demonstrates unsafe handling, and body-based transport is not generally suitable for GET requests. No header-based authentication mechanism is documented.
Attack Path
- A user copies the documented command and replaces
yuri_sk_XXXXXwith an active Yuri token. - The command containing the token is retained in shell history, or the complete request URL is captured by gateway, proxy, CDN, observability, or diagnostic logs.
- An attacker or unauthorized operator with access to one of those records extracts the token.
- The attacker sub ...[truncated 897 chars]
- A user copies the documented command and replaces
- Remediation
View remediation
Remediation Suggestions
- Add support for sending the Yuri token in an
Authorizationheader and make that mechanism the default in every example. - If query-string authentication must remain for compatibility, clearly label it as a legacy or last-resort mechanism rather than presenting it as the primary quick-start pattern.
- Provide copyable examples that avoid placing literal credentials in command arguments. Read the token from a protected environment variable or secret manager while accounting for command-line and process-inspection risks.
- Configure the gateway, load balancers, reverse proxies, CDNs, application monitoring, and error-reporting systems to redact
access_tokenvalues before storage or transmission. - Avoid logging complete query strings. Where request targets must be logged, use an explicit parameter allowlist and replace credential values with a fixed redaction marker.
- Use short-lived, least-privilege, narrowly scoped tokens and provide automated rotation and immediate revocation controls.
- Add secret-detection monitoring for operational logs and establish an incident procedure that revokes any token found in a URL or log.
- Update the quick-start documentation to demonstrate the secure authentication method first and explain that TLS alone does not prevent credential retention at endpoints.
- Add support for sending the Yuri token in an
