T09 · Insecure Skill Coding Practices
- Location
scripts/scrape_web.py:43- Finding
Plaintext Exposure of Sensitive Form Data Through Process Arguments and Standard Output
- Content
View full analysis
Vulnerability Details
File Location:
scripts/scrape_web.py, lines 43-48 and 76-78
Vulnerability Type: Plaintext sensitive-data exposure
Risk Level: MediumVulnerable Code
python results = { "url": url, "form_data": form_data, "status": "submitted", "response": "Form submitted successfully" }python url = sys.argv[2] form_data = json.loads(sys.argv[3]) result = fill_form(url, form_data) print(json.dumps(result, indent=2))Technical Analysis
The
fill-formaction accepts the complete form payload as a command-line argument. Command-line arguments may be exposed through process inspection tools, shell history, command auditing, or process-monitoring systems.The
fill_form()function then includes the unredacted input in theform_dataresult property. The CLI serializes that result to standard output without filtering sensitive field names or values. Standard output is frequently retained by Agent runtimes, CI/CD systems, terminal capture tools, and centralized logging services.Form data commonly contains passwords, access tokens, personal information, session values, or payment-related details. Consequently, this behavior creates multiple plaintext disclosure channels. The function also reports a successful submission even though no network request occurs, which may mislead callers about the operation's result.
Attack Path
- A user or Agent invokes the
fill-formaction and supplies sensitive fields in the JSON command-line argument. - The operating system exposes that argument to any local process or monitoring facility authorized to inspect the process command line.
- The script parses the JSON and copies every supplied value into
results["form_data"]. - The script serializes the complete result to standard output.
- Terminal history, Agent execution records, CI logs, or centralized logging systems may retain the exposed values ...[truncated 1027 chars]
- A user or Agent invokes the
- Remediation
View remediation
Remediation Suggestions
- Do not accept confidential form values through command-line arguments. Read them from standard input, an appropriately permission-restricted file, or a dedicated secret-management interface.
- Remove the
form_dataproperty from the returned result. If diagnostic information is required, return only non-sensitive field names or a redacted summary. - Implement explicit redaction for common sensitive fields such as
password,token,secret,authorization,cookie, and payment-related values. Prefer allowlisting safe metadata over relying solely on field-name matching. - Ensure logs and exception messages never include raw form payloads.
- Return a truthful operation state. Do not report
"submitted"or"Form submitted successfully"unless an actual submission has completed successfully and its response has been validated. - Add automated tests verifying that secrets supplied to the form workflow do not appear in returned objects, standard output, error output, or log records.
- Document secure input handling requirements and advise operators to restrict access to execution logs and apply suitable retention policies.
