Back to skill

Security audit

Douyin Creator Marketplace (Xingtu) Audience Distribution API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused JustOneAPI client, but it handles the required API token in ways that can expose it through process arguments and URL query logging.

Install only if you are comfortable sending a JustOneAPI token to api.justoneapi.com in the URL query string and exposing it briefly in the Node process command line. Prefer a short-lived, least-privileged token, avoid verbose command logging, and rotate the token if it may have appeared in shell history, process telemetry, proxy logs, or error reports.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:23
Finding

API Token Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The resulting URL, containing the plaintext token in its query string, is then supplied to `fetch`: ```javascript const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, }; response = await fetch(url, requestInit); ``` HTTPS protects the request while it is in transit, but it does not prevent credential exposure through local process inspection or URL logging. Command-line arguments may be visible to other authorized local users, process-monitoring agents, crash diagnostics, shell history, or orchestration telemetry. Query strings may be retained by reverse proxies, API gateways, access logs, tr ...[truncated 2326 chars]
Remediation
View remediation
"}' ``` 6. Rotate any token suspected of having appeared in process telemetry, command history, access logs, traces, or diagnostic output. 7. Add automated tests verifying that tokens never appear in generated URLs, standard output, standard error, or error objects. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and is explicitly designed to call a remote API, but it does not declare any tool scope such as permissions or allowed-tools. This creates a mismatch between documented capability and declared restrictions, which weakens policy enforcement and reviewability by making outbound network access implicit rather than explicitly authorized.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill defines the authentication token as a query parameter and automatically appends it to the request URL. Query-string tokens are commonly exposed through logs, browser/history artifacts, reverse proxies, monitoring systems, and downstream error reports, which increases the chance of credential leakage even when HTTPS is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The API requires a sensitive authentication token to be sent in the URL query string, which is commonly logged by clients, servers, proxies, browser history, and monitoring systems. Even over HTTPS, query parameters often appear in operational logs and analytics, increasing the chance of credential leakage and unauthorized API access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.