Back to skill

Security audit

Douyin (TikTok China) Share Link Resolution API

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it handles the required API token in ways that can expose it through process or URL logs.

Review this before installing if the JustOneAPI token has billing privileges, broad account access, or long lifetime. Prefer a version that reads the token from the environment internally and sends authentication in a header, or use a tightly scoped, revocable token and ensure URL and process logs redact it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:24
Finding

API Token Exposure Through Command-Line Arguments and URL Query Parameters

Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The documented invocation also places the token in a command-line argument: ```bash node {baseDir}/bin/run.mjs --operation "shareDouyinUrlTransferV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"shareUrl":""}' ``` ### Technical Analysis The Skill sends the API token to the declared JustOneAPI endpoint as ...[truncated 2993 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The API requires an access token to be sent as a query parameter, which is a real credential-handling weakness. Query-string tokens are commonly exposed through logs, browser history, monitoring systems, proxy caches, referrer leakage, and analytics tooling, increasing the chance of accidental credential disclosure even when HTTPS is used.

Content

Scanner excerpt · generated/operations.json (reported line 15)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for this API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/run.mjs (reported line 20)May include surrounding context.

js
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `shareUrl` | `query` | yes | `string` | n/a | The Douyin short share URL. |

### Request body

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 19)May include surrounding context.

md
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `shareUrl` | `query` | yes | `string` | n/a | The Douyin short share URL. |

### Request body

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and requires an API token, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates a trust and containment gap: an agent runtime may permit broader networked behavior than reviewers or users expect, increasing the chance of unintended external requests or data exfiltration through the helper.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill defines the API token as a query parameter and later appends all query parameters to the request URL. Query-string credentials are routinely exposed through logs, browser/history tooling, proxies, monitoring systems, and error messages, which increases the chance of credential leakage even when HTTPS is used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.