T09 · Insecure Skill Coding Practices
- Location
SKILL.md:46- Finding
GitHub Authentication Token Exposed Through Process Arguments
- Content
View full analysis
/imgN.png ``` ### Technical Analysis The command substitutes the output of `gh auth token` directly into a `curl` command-line argument. After shell expansion, the complete GitHub token becomes part of the running process's argument vector as an HTTP `Authorization` header. Depending on the host configuration, command-line arguments may be observable through process inspection interfaces, monitoring agents, diagnostic tooling, audit logs, or process-listing utilities. A local user or compromised process with sufficient visibility could capture the token while `curl` is running. Authentication is legitimately required to download attachments from private GitHub repositories. However, placing the credential in process arguments exceeds the minimum necessary exposure for that operation. The use of `curl -L` also permits redirects, so redirect behavior and destination hosts should be restricted even when the client is expected to suppress credentials across host boundaries. ### Attack Path 1. A user asks the agent to read an issue containing an authenticated private-repository attachment. 2. The Skill runs the documented command and invokes `gh auth token`. 3. The shell expands the token into the `curl` argument containing the `Authorization` header. 4. While `curl` is active, a local attacker, compromised monitoring component, or other process with permission to inspect process arguments captures the expanded header. 5. The attacker extracts the bearer token and submits authenticated requests to GitHub. 6. The attacker gains access up to the permissions and repository scope granted to that token, until it expires or is revoked. This path requires local process visibility or access to tool ...[truncated 832 chars]- Remediation
View remediation
