Back to skill

Security audit

IMDb Contribution Questions API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow JustOneAPI IMDb lookup helper, but it places the user's API token in the request URL, which can expose the token through logs or telemetry.

Review this before installing if you will use a valuable JustOneAPI token. The skill is not trying to hide its API call, but its current authentication pattern can place the token in URLs that may be logged by infrastructure. Prefer a low-scope, revocable token and rotate it if you suspect exposure.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:20
Finding

API Authentication Token Exposed in URL Query Parameter

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs, lines 20–28, 89–101, and 231–241
Vulnerability Type: Sensitive credential transmitted in a URL query parameter
Risk Level: Medium

Vulnerable Code

js
{
  "defaultValue": null,
  "description": "User's authentication token.",
  "enumValues": [],
  "location": "query",
  "name": "token",
  "required": true,
  "schemaType": "string"
}
js
const params = parseParams(args.paramsJson);
applyDefaults(operation, params);
injectToken(operation, params, args.token);
validateRequired(operation, params);

const baseUrl = manifest.baseUrl;
const url = new URL(operation.path, ensureBaseUrl(baseUrl));
applyPathParams(operation, params, url);
applyQueryParams(operation, params, url);
js
function applyQueryParams(operation, params, url) {
  for (const parameter of operation.parameters.filter((item) => item.location === "query")) {
    const value = params[parameter.name];
    if (value === undefined) {
      continue;
    }
    appendValue(url.searchParams, parameter.name, value);
  }
}

The same query-based authentication scheme is documented in generated/operations.json, lines 16–24, and generated/operations.md, line 16.

Technical Analysis

The Skill receives the user's JustOneAPI authentication token and inserts it into params.token. Because the operation manifest defines token as a query parameter, applyQueryParams() appends the credential to the request URL. The resulting request has the form:

text
https://api.justoneapi.com/api/imdb/title-contribution-questions/v1?token=<secret>&id=<title-id>&languageCountry=<locale>

HTTPS encrypts the URL while it is in transit, but it does not prevent the complete URL from being recorded at endpoints or inside trusted infrastructure. Query strings are commonly captured by reverse-proxy access logs, API gateway logs, observability platforms, debugging tools, error reports, and monitoring systems. This unnecessarily expa ...[truncated 1671 chars]

Remediation
View remediation

Remediation Suggestions

  1. Use an authentication header supported by the provider, preferably:

    js
    const requestInit = {
      headers: {
        accept: "application/json",
        authorization: `Bearer ${args.token}`,
      },
      method: operation.method,
    };
    

    If JustOneAPI uses a dedicated API-key header, use that header instead of Authorization.

  2. Remove token from the operation's query-parameter definitions in:

    • bin/run.mjs
    • generated/operations.json
    • generated/operations.md
  3. Keep credentials separate from general request parameters. Explicitly reject token, authorization, and other credential-like fields supplied through --params-json so they cannot be accidentally serialized into a URL.

  4. Ensure request diagnostics, telemetry, and error handling redact authorization headers and sensitive query parameters. Never print the token or a complete credential-bearing URL.

  5. If the upstream API only supports query-based authentication:

    • Document the residual credential-exposure risk.
    • Configure all clients, proxies, gateways, servers, and monitoring systems to redact the token parameter.
    • Apply short token lifetimes, least-privilege scopes, rotation, revocation, and usage alerts.
    • Avoid retries or exception messages that could reproduce the request URL.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a network-capable helper (node {baseDir}/bin/run.mjs) and requires an API token, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity: a host agent may permit network execution without the skill transparently declaring it, reducing reviewability and increasing the chance of unintended outbound requests or token use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill requires the authentication token to be sent as a query parameter and automatically injects it into the URL before issuing the request. Query-string secrets are commonly exposed through logs, browser/history artifacts, proxy/CDN telemetry, monitoring systems, and error traces, so the token can be disclosed even when HTTPS is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Passing an authentication token in the query string is dangerous because query parameters are commonly logged by servers, proxies, gateways, browser history, analytics tools, and monitoring systems. Even when HTTPS is used, the token may still be exposed through operational logs or accidental URL sharing, leading to credential leakage and unauthorized API access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The markdown specifies a limited set of languageCountry values and presents them as the available language/country preferences, but does not state that the user should choose or opt in to a locale. This can create a natural-language locale policy concern because the skill may steer output or requests into a specific locale set without explicit user preference handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON file functions as a manifest/interface definition, so SQP-1 applies. The descriptions identify the API capability but provide no explicit invocation boundaries, trigger phrases, or negative examples, making it unclear when this skill should activate versus other IMDb-related skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.