T09 · Insecure Skill Coding Practices
- Location
SKILL.md:44- Finding
API token exposed through command-line arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a focused IMDb rankings API skill, but its token handling can expose the user's API credential through process arguments and request URLs.
Review this before installing if you are sensitive to API-token exposure. Use a narrowly scoped JustOneAPI token, avoid shared machines or process telemetry that records command arguments, and rotate the token if full request URLs or command lines may have been logged.
SKILL.md:44API token exposed through command-line arguments
bin/run.mjs:201API token transmitted as a URL query parameter
The skill invokes a networked API and includes runnable helper instructions, but it does not declare any explicit tool scope such as allowed tools or permissions. That creates an authorization and review gap: a host agent may permit broader network behavior than intended, and users or orchestrators cannot clearly enforce least-privilege constraints for this skill.
The skill defines the authentication token as a query parameter and appends it to the request URL, which causes the secret to appear in places URLs are commonly logged or exposed, such as shell history, proxy logs, browser/debug tooling, observability systems, and upstream server access logs. Although the request is sent over HTTPS, query-string placement still increases credential disclosure risk compared with using an Authorization header.
The operation requires a user authentication token to be sent in the URL query string, which is an insecure pattern because query parameters are commonly captured in server logs, browser history, intermediary proxies, analytics systems, and error traces. Even when HTTPS is used, this design increases the chance of credential exposure and unauthorized reuse of the token beyond its intended scope.
This markdown file describes the skill's purpose and endpoint but does not specify how narrowly the skill should be invoked or provide exclusion conditions. Without explicit trigger scope or negative examples, an agent may over-apply the skill whenever IMDb rankings are mentioned.
No suspicious patterns detected.