Kuaishou User Published Videos API

Security checks across malware telemetry and agentic risk

Overview

This is a narrow JustOneAPI helper for fetching Kuaishou published-video data, with the main caution being careful handling of the API token.

Install only if you trust JustOneAPI and are comfortable sending your JUST_ONE_API_TOKEN to api.justoneapi.com. Keep the token in the environment, avoid pasting it into chats or logs, and treat command lines or URLs containing the token as sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill defines the API access token as a query parameter and later appends all query parameters directly to the request URL. Query-string credentials are commonly exposed through logs, browser/history tooling, proxy caches, monitoring systems, and error messages, making accidental credential leakage significantly more likely even when HTTPS is used.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal