Back to skill

Security audit

Douyin Creator Marketplace (Xingtu) API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent JustOneAPI wrapper, but it handles the required API token in exposure-prone ways that deserve Review before install.

Install only if you are comfortable using a JustOneAPI token in an environment where command lines and request URLs may be logged. Prefer a scoped, revocable token, avoid shared or heavily monitored hosts, review the generated operations before use, and rotate the token if it may have appeared in logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:2758
Finding

Authentication Token Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
" --token "$JUST_ONE_API_TOKEN" --params-json '{"key":"value"}' ``` The runner reads the secret from `process.argv`: ```javascript function parseArgs(argv) { const parsed = { operation: null, paramsJson: "{}", token: null }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); } return parsed; } ``` It then inserts the supplied credential into the general parameter object: ```javascript function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` Because the operati ...[truncated 4379 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
- Get a token from [Just One API Dashboard](https://dashboard.justoneapi.com/en/login?utm_source=clawhub.ai&utm_medium=referral&utm_campaign=justoneapi_douyin_xingtu&utm_content=project_link).
- Authentication details: [Just One API Usage Guide](https://docs.justoneapi.com/en/?utm_source=clawhub.ai&utm_medium=referral&utm_campaign=justoneapi_douyin_xingtu&utm_content=project_link).

## Output Rules

- Start with a plain-language answer tied to the Douyin Creator Marketplace (Xingtu) task the user asked for.
- Include the most decision-relevant fields from the selected endpoint before dumping raw JSON.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to execute a Node helper that performs authenticated external API requests, but the manifest does not declare an explicit tool scope such as permissions or allowed-tools. This creates an authorization-boundary problem: the skill’s effective capabilities are broader and less transparent than its declared policy, increasing the chance of unintended network access or unsafe invocation in environments that rely on manifest scoping for enforcement or review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description materially understates the skill's true capabilities by describing only a narrow subset of analytics functions while the code exposes many additional search, creator-discovery, and item-report endpoints. This can mislead users, reviewers, or policy enforcement into granting the skill broader access than expected, increasing the risk of unintended data access and abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This skill sends authentication tokens as query parameters, and the code appends them directly into the URL before issuing requests. Query-string tokens are commonly exposed through logs, browser history, proxy telemetry, server access logs, and monitoring systems, making credential leakage more likely than if the token were sent in an Authorization header.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description materially understates the skill’s capabilities by advertising only a narrow subset of functions while the OpenAPI spec exposes broad creator analytics, search, discovery, item reports, and conversion-related operations. This mismatch can mislead users, reviewers, or policy controls about what data the skill can access and process, increasing the risk of inappropriate use or over-broad authorization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Passing authentication tokens in query parameters is dangerous because URLs are commonly logged by clients, proxies, gateways, observability tools, browser history, and server access logs, causing credential exposure outside the intended trust boundary. In this skill, the risk is amplified because nearly all operations require a token and repeatedly transmit it this way across a broad analytics/search API surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Placing authentication tokens in query parameters is dangerous because query strings are commonly logged by servers, proxies, analytics systems, browser history, and monitoring tools. In a skill context, this increases the chance that credentials are exposed through routine observability or accidental sharing, enabling unauthorized API access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented skill scope materially understates what the operations actually expose. A user or orchestrating agent may trust the manifest description and invoke the skill expecting limited creator-profile analysis, while the skill also supports broader creator search, pricing, audience, conversion, item-report, and video-detail retrieval, increasing the risk of unintended data access and over-privileged use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.