Summary
gl name register takes the wallet-controlling --private-key as a plain string argument (also via ETH_PRIVATE_KEY env, crates/gl/src/name.rs:67-68, :109), and gl task create takes --ucan_token (crates/gl/src/task.rs:37), which is sent in the task JSON (task.rs:164) and stored by the node (gitlawb-node/src/api/tasks.rs:40,83,113).
Impact
Command-line arguments are visible process-wide (process listings, WMI, shell history). The wallet key is the direct concern; the UCAN token is additionally persisted in task records readable through the feed (see #268). The node's iss == signer check (auth/mod.rs:281) prevents replay as the delegator, so this is capability-graph disclosure rather than immediate privilege. #354/#459 cover the file-permission channel; this is the argv channel.
Remediation
- Read the private key from a file or hidden prompt instead of argv.
- Prefer the stored UCAN from
ucan.json over a flag; document argv as unsupported.
Proposed labels: kind:security, crate:gl, subsystem:identity.
Summary
gl name registertakes the wallet-controlling--private-keyas a plain string argument (also viaETH_PRIVATE_KEYenv,crates/gl/src/name.rs:67-68,:109), andgl task createtakes--ucan_token(crates/gl/src/task.rs:37), which is sent in the task JSON (task.rs:164) and stored by the node (gitlawb-node/src/api/tasks.rs:40,83,113).Impact
Command-line arguments are visible process-wide (process listings, WMI, shell history). The wallet key is the direct concern; the UCAN token is additionally persisted in task records readable through the feed (see #268). The node's
iss == signercheck (auth/mod.rs:281) prevents replay as the delegator, so this is capability-graph disclosure rather than immediate privilege. #354/#459 cover the file-permission channel; this is the argv channel.Remediation
ucan.jsonover a flag; document argv as unsupported.Proposed labels: kind:security, crate:gl, subsystem:identity.