Back to skill

Security audit

IMDb Countries of Origin API

Security checks for vulnerabilities and agentic risk

Overview

This is a focused JustOneAPI wrapper for one IMDb lookup endpoint, with a real credential-handling caveat but no evidence of hidden, destructive, persistent, or unrelated behavior.

Install only if you are comfortable giving this skill a JustOneAPI token for the documented IMDb lookup. Prefer a narrowly scoped token if available, avoid pasting token values into chat or logs, and rotate the token if you suspect command-line history, process monitoring, proxy logs, or API logs may have captured request URLs containing the token.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:236
Finding

API Token Exposed Through Command-Line Arguments and URL Query Parameters

Content
View full analysis
item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The documented invocation also passes the secret through a command-line argument: ```bash node {baseDir}/bin/run.mjs --operation "titleCountriesOfOrigin" --token "$JUST_ONE_API_TOKEN" --params-json '{"id":""}' ``` ### Technical Analysis Sending ...[truncated 3297 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill requires the authentication token to be placed in the URL query string, which is commonly logged by client tooling, proxies, browser history, observability systems, and upstream servers. Even though the request uses HTTPS, query parameters are still more broadly exposed than headers, making accidental credential leakage more likely in normal operation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The languageCountry parameter defaults to en_US, which means the skill will prefer US English even when the user has not selected a language or locale. This is a natural-language policy concern because the file does not present the locale choice as opt-in despite supporting multiple locales.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This manifest file describes the skill in broad functional terms but does not define any explicit trigger phrases, scope boundaries, or exclusion conditions. In systems that infer invocation from descriptions, the generic wording around IMDb countries-of-origin lookup may be too underspecified to clearly distinguish when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.