Back to skill

Security audit

IMDb 'Did You Know' Insights API

Security checks for vulnerabilities and agentic risk

Overview

This skill is narrowly focused on an IMDb lookup API, but it sends the user's JustOneAPI token in the URL query string, which increases the chance of token exposure in logs or monitoring systems.

Review this before installing if the JustOneAPI token has meaningful quota, billing, or account scope. Use a narrowly scoped, revocable token if possible, avoid putting token-bearing URLs in logs or tickets, and rotate the token if it may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:19
Finding

API Authentication Token Transmitted in the URL Query String

Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The resulting URL, including the token, is sent to the fixed JustOneAPI HTTPS endpoint: ```js let response; try { response = await fetch(url, requestInit); } catch (error) { fail("Network request failed.", { cause: error instanceof Error ? error.message : String(error), ...[truncated 2600 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill requires an authentication token to be supplied as a query parameter and then appends it into the request URL. Query-string credentials are routinely exposed through logs, browser/history tooling, reverse proxies, monitoring systems, and error reporting, making token leakage more likely than if the token were sent in an Authorization header.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Documenting an authentication token as a query parameter encourages credential transmission in URLs, which are commonly logged by clients, proxies, gateways, browser history, and monitoring systems. Even though this is API documentation rather than executable code, it normalizes an unsafe auth pattern and increases the chance of accidental token exposure during routine use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The languageCountry parameter defaults to en_US, which means the skill will select English (US) when the user does not choose a locale. This is a natural-language locale policy concern because it forces a specific language/region preference by default rather than requiring user selection or explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest sets a default languageCountry value of en_US, which causes the skill to prefer a specific language/locale unless the caller overrides it. The file does list other supported locales, but it does not indicate user choice or opt-in for the default, which can conflict with locale preference policies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The parameter documentation sets en_US as the default language/country preference, which imposes a specific locale when the user does not choose one. The file does not state that users can or should select their preferred locale before the default is applied.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.