Back to skill

Security audit

Beike Community List API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused API wrapper for one Beike housing endpoint, with credential-handling cautions but no evidence of hidden or unrelated behavior.

Install only if you are comfortable using a JustOneAPI token for Beike community-list queries. Prefer a narrowly scoped, revocable token, avoid pasting token values into chat or logs, and be aware that this version passes the token as a command-line argument and query parameter.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:204
Finding

API Token Exposed Through Command-Line Arguments and URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:41,50; bin/run.mjs:24-31,81-85,204-212,226-235
Vulnerability Type: Credential exposure through process arguments and URL query strings
Risk Level: Medium

The documented invocation passes the API token as a command-line argument:

bash
node {baseDir}/bin/run.mjs --operation "communityListV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"cityId":"<cityId>"}'

The executable defines the token as a required query parameter:

js
{
  "defaultValue": null,
  "description": "User authentication token.",
  "enumValues": [],
  "location": "query",
  "name": "token",
  "required": true,
  "schemaType": "string"
}

It then injects the command-line token into the request parameters:

js
function injectToken(operation, params, cliToken) {
  const tokenParam = operation.parameters.find((parameter) => parameter.name === "token");
  if (!tokenParam || params.token !== undefined) {
    return;
  }
  if (!cliToken) {
    fail("--token is required for this operation.", {
      operationId: operation.operationId,
    });
  }
  params.token = cliToken;
}

Every parameter marked as a query parameter, including token, is appended to the URL:

js
function applyQueryParams(operation, params, url) {
  for (const parameter of operation.parameters.filter((item) => item.location === "query")) {
    const value = params[parameter.name];
    if (value === undefined) {
      continue;
    }
    appendValue(url.searchParams, parameter.name, value);
  }
}

Technical Analysis

Authentication tokens are sensitive credentials and should not be placed in process command lines or URL query strings.

Passing the token with --token may expose it through process listings, process-monitoring software, shell history when literal values are used, job-control metadata, diagnostic tooling, or command exec ...[truncated 2225 chars]

Remediation
View remediation

Remediation Suggestions

  1. Read the token directly from process.env.JUST_ONE_API_TOKEN instead of accepting it through --token.
  2. Remove or deprecate the command-line token option so the secret is not present in the process argument vector.
  3. If the upstream API supports it, send the credential in an authorization header, such as:
    js
    const token = process.env.JUST_ONE_API_TOKEN;
    requestInit.headers.authorization = `Bearer ${token}`;
    
  4. Remove token from the operation's query-parameter definition and reject a token property supplied through --params-json.
  5. If the upstream service mandates query-based authentication, request support for header-based authentication. Until then, configure API gateways, proxies, tracing systems, and server logs to redact the token parameter.
  6. Avoid logging complete request URLs, request options, process arguments, or error objects that might contain credentials.
  7. Use short-lived, narrowly scoped tokens with rotation, revocation, quota limits, and endpoint restrictions.
  8. Update SKILL.md so examples rely on the environment variable internally rather than forwarding its value through a command-line option.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and is explicitly designed to call an external API, but it does not declare any tool scope such as permissions or allowed-tools. This creates a policy gap where the runtime may allow broader tool or network access than users and reviewers can infer from the manifest, reducing transparency and increasing the risk of unintended external requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The operation requires a user authentication token as a query parameter, and the script injects and sends it via an HTTP request. While the code validates the token requirement, there is no confirmation prompt, user-facing log/warning, or comment/docstring disclosing that sensitive credential material will be transmitted to an external API.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This is a JSON manifest file, so vague-trigger checks apply. The description and operation summary explain what the API does, but they do not define explicit activation phrases, exclusions, or narrow invocation context, which can make trigger behavior ambiguous if this manifest is used for automatic skill routing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
67% confidence
Finding

The parameter description uses an English-only example for the city identifier and the file provides no indication that language or locale is selectable or intentionally constrained. Because this skill targets location-specific housing data, the lack of an explicit locale or language policy can be a minor organizational policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.