T09 · Insecure Skill Coding Practices
- Location
scripts/creative_list.py:689- Finding
Credential Exposure Through Command-Line Arguments and Dry-Run Output
- Content
View full analysis
" print(_json_dumps({ "url": f"{BASE_URL}{canonical_uri}", "headers": safe_headers, "body": payload, })) return 0 ``` ### Technical Analysis The script supports passing both the access-key ID and access-key secret as command-line arguments. Command-line secrets can be exposed through shell history, process inspection facilities, process-monitoring software, CI job metadata, diagnostic reports, or command logging. Although the documented usage recommends environment variables, the command-line options remain available and create an avoidable credential-exposure path. This exceeds the minimum privilege and disclosure requirements of the declared functionality because the secret only needs to be available internally for HMAC signing and does not need to appear in process arguments. Dry-run mode also performs incomplete redaction of the `Authorization` header. It replaces only the signature while retaining the `Credential=` component. This conflicts with the Skill documentation's instruction n ...[truncated 2073 chars]- Remediation
View remediation
" ``` 5. Consider redacting or omitting the customer name and access-key ID from all diagnostic output unless explicitly required for troubleshooting. 6. Add automated tests that verify neither the access-key ID nor the access-key secret appears in dry-run output, standard output, error messages, or exception text. 7. Rotate any credentials that may previously have been supplied through command-line arguments or retained in shared terminal and CI logs. ]]>
