Back to skill

Security audit

IMDb News by Category API

Security checks for vulnerabilities and agentic risk

Overview

This skill is narrowly scoped to fetching IMDb category news, but it sends the user's JustOneAPI token in the request URL, which can expose the credential in logs or monitoring systems.

Review before installing if you use a sensitive, paid, or broad JustOneAPI token. Prefer a scoped or low-quota token, rotate it if it may have been logged, and be aware that this skill sends the token as part of the request URL rather than only in a protected header.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:25
Finding

API Authentication Token Exposed in URL Query String

Content
View full analysis
item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The same query-string authentication requirement is declared in `generated/operations.json:15-22` and `generated/operations.md:18`. ### Technical Analysis The authentication token is defined as a query parameter. After `injectToken` places the supplied credential in `params.token`, `applyQueryParams` serializes it into the request URL. The resulting request has the form: ```text https://api.justoneapi.com/api/imdb/news-by-category-query/v1?token=&category=TOP ``` Sending an authentication credential to the declared JustOneAPI endpoint is necessary for the Skill's functionality. However, placing the credential in the URL creates unnecessary exposure. Complete URLs are commonly retained by API gateways, reverse proxies, access logs, observability systems, debugging tools, and server-side request telemetry. HTTPS protects the URL while it is in transit but does not prevent authorized intermediaries or endpoint infrastructure from rec ...[truncated 1526 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill sends the authentication token as a query parameter, which places the secret in the full request URL. URLs are commonly logged by clients, proxies, gateways, browser/history layers, and observability systems, so the token can be exposed outside the intended trust boundary even when HTTPS is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The operation defines an authentication token as a query parameter, which is a real security weakness because query strings are commonly logged by clients, proxies, gateways, browser history, and server access logs. In this skill's context, the token is the primary secret for accessing the third-party API, so exposure could enable unauthorized API use, account abuse, or quota consumption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Documenting an authentication token as a query parameter is a real security weakness because query strings are commonly logged by servers, proxies, browser history, analytics tools, and monitoring systems. In this skill context, the risk is increased because the operation definition may encourage downstream integrators and agents to transmit reusable credentials in URLs, making accidental credential leakage more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The parameter definition sets the default languageCountry to en_US, which forces a specific language/locale when the user does not choose one. The file does list other supported locales, but it does not indicate user opt-in or a justified region-specific constraint for the default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.