Back to skill

Security audit

Idx Market Data

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward IDX market-data helper, but users should treat GoAPI request URLs as sensitive because the API key is placed in the query string.

Install only if you are comfortable sending IDX lookup requests to GoAPI and using a GOAPI_KEY with this skill. Treat any full request URL containing api_key as secret: do not paste it into chats, logs, screenshots, or bug reports, and rotate the key if it is exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

API Credential Exposure Through URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–20
Vulnerability Type: API credential exposure through query-string authentication
Risk Level: Medium

Vulnerable Code

markdown
## Format Autentikasi
**PENTING:** Gunakan query parameter, BUKAN header Authorization.
text
https://api.goapi.io/stock/idx/companies?api_key={GOAPI_KEY}

The same credential-bearing URL pattern is also used in the endpoint examples on lines 26, 31, 36, and 41.

Technical Analysis

The skill explicitly instructs the agent to place GOAPI_KEY in the URL query string instead of an authorization header. Although HTTPS encrypts the request in transit, query strings are commonly retained by HTTP clients, reverse proxies, access logs, monitoring systems, debugging tools, exception reports, and agent/tool transcripts.

Consequently, a request URL recorded by any intermediary may expose the complete API credential. An attacker with access to such records could extract and replay the key without needing to compromise the encrypted network connection.

Attack Path

  1. A user configures a valid GOAPI_KEY.
  2. The skill constructs a request such as: https://api.goapi.io/stock/idx/companies?api_key=SECRET_VALUE.
  3. The complete URL is captured in client history, proxy logs, observability telemetry, debugging output, error reports, or tool transcripts.
  4. An attacker or unauthorized log reader obtains the recorded URL.
  5. The attacker extracts SECRET_VALUE and submits requests directly to GoAPI.
  6. The attacker continues using the credential until it is revoked, rotated, or otherwise expires.

Impact Assessment

Exploitation can grant unauthorized use of the affected GoAPI account within the permissions and limits assigned to the exposed key. This may allow an attacker to retrieve API data, consume request quotas, cause service disruption through quota exhaustion, or incur account charges ...[truncated 175 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer an Authorization header or another non-URL authentication mechanism supported by GoAPI.
  2. If GoAPI only supports query-string authentication, ensure clients, proxies, monitoring systems, and agent tools redact the api_key parameter before recording URLs.
  3. Never display or return fully expanded credential-bearing URLs in agent responses, errors, or diagnostic output.
  4. Use narrowly scoped, short-lived API keys where the provider supports them.
  5. Apply strict access controls and short retention periods to logs that may contain request metadata.
  6. Configure quota and billing alerts to detect unauthorized use promptly.
  7. Rotate the key immediately if a complete request URL has been logged or otherwise disclosed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs placing the API key in the URL query string, which increases the chance the secret will be exposed through logs, browser history, proxy logs, telemetry, error messages, and referrer-like handling in downstream tooling. Even if the upstream API supports this format, embedding credentials in URLs is a well-known secret-handling weakness and the skill provides no warning or mitigation guidance.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

The skill directs the agent to transmit data to an external third-party service, which is an actual data-flow/security concern because user queries and associated request metadata leave the local trust boundary. In this context the risk is elevated by the adjacent instruction to include the API key in the URL, compounding the possibility of credential leakage during external requests.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

Format Autentikasi

PENTING: Gunakan query parameter, BUKAN header Authorization.

text
https://api.goapi.io/stock/idx/companies?api_key={GOAPI_KEY}

Endpoint Utama & Penggunaan

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The description, instructions, and examples are entirely in Indonesian and the skill is framed around Indonesian-market use, but it does not explicitly state that the locale/language is intentionally limited or provide user opt-in. Under the policy, forcing a specific language without choice or justification can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.