Back to skill

Security audit

IMDb Plot Summary API

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its API token handling exposes a user credential through command-line arguments and URL query parameters.

Review this skill before installing if the JustOneAPI token has billing, quota, or broad account authority. Use a narrowly scoped token if possible, avoid shell tracing or process logging while running it, and rotate the token if it may have appeared in command logs or URL logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:87
Finding

API Token Exposed Through Command-Line Arguments and URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:87-111, bin/run.mjs:151-175, bin/run.mjs:199-210, and bin/run.mjs:242-264; documented usage at SKILL.md:43-49
Vulnerability Type: Sensitive credential exposure through process arguments and URL query data
Risk Level: Medium

The Skill requires an API credential for its declared IMDb plot-summary functionality. Sending authentication information to the fixed JustOneAPI endpoint is necessary, but exposing the token through both the command line and request URL exceeds the minimum-risk authentication design.

Vulnerable Code

The documented invocation passes the secret as a command-line argument:

bash
node {baseDir}/bin/run.mjs --operation "titlePlotQuery" --token "$JUST_ONE_API_TOKEN" --params-json '{"id":"<id>"}'

The helper parses the token directly from the process argument vector:

js
function parseArgs(argv) {
  const parsed = { operation: null, paramsJson: "{}", token: null };
  for (let index = 0; index < argv.length; index += 1) {
    const flag = argv[index];
    const value = argv[index + 1];
    if (flag === "--operation") {
      parsed.operation = value;
      index += 1;
      continue;
    }
    if (flag === "--params-json") {
      parsed.paramsJson = value;
      index += 1;
      continue;
    }
    if (flag === "--token") {
      parsed.token = value;
      index += 1;
      continue;
    }
    fail(`Unknown argument "${flag}".`);
  }
  return parsed;
}

It then places the token into the same parameter object used to construct query parameters:

js
function injectToken(operation, params, cliToken) {
  const tokenParam = operation.parameters.find((parameter) => parameter.name === "token");
  if (!tokenParam || params.token !== undefined) {
    return;
  }
  if (!cliToken) {
    fail("--token is required for this operation.", {
      operationId: operat
...[truncated 4466 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the --token argument and read the credential directly from process.env.JUST_ONE_API_TOKEN inside the Node.js process. This prevents routine command-line inspection from revealing the value.
  2. Prefer an authentication header supported by the service, such as Authorization: Bearer ..., rather than a query parameter.
  3. If the upstream API only supports query-string authentication, request or implement a header-based authentication option. Until then, configure clients, reverse proxies, gateways, and server logging systems to redact the token parameter.
  4. Ensure errors and diagnostics never serialize the complete request URL or parameter object after token injection.
  5. Reject token inside --params-json so callers cannot bypass the intended secret-loading mechanism.
  6. Use narrowly scoped, short-lived tokens where supported, rotate any token suspected of appearing in process or URL logs, and apply account-level rate and billing alerts.
  7. Update SKILL.md so the example invokes the helper without a token argument:
bash
JUST_ONE_API_TOKEN="$JUST_ONE_API_TOKEN" \
  node {baseDir}/bin/run.mjs \
  --operation "titlePlotQuery" \
  --params-json '{"id":"<id>"}'

The implementation should then obtain the value through process.env.JUST_ONE_API_TOKEN and place it in a protected authentication header.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill invokes a network-capable helper (node {baseDir}/bin/run.mjs) to call an external API, but the manifest does not explicitly declare tool scope such as permissions or allowed-tools. This creates a policy/visibility gap: consumers and enforcement layers cannot clearly restrict or audit the skill's network behavior, increasing the chance of unintended external requests and data exfiltration through the documented API path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill sends the authentication token as a query parameter, which causes it to be embedded in the full request URL. URLs are commonly logged by clients, proxies, observability tools, browser history, and upstream infrastructure, so the token can be exposed outside its intended boundary and reused by anyone who obtains those logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Passing an authentication token in the query string is dangerous because query parameters are commonly exposed in logs, browser history, analytics systems, intermediary proxies, and referrer data. In this skill, the token is explicitly required as a query parameter and there is no disclosure or safer alternative, creating unnecessary credential exposure risk during normal use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The operation documents an authentication token as a query parameter, which is risky because query strings are commonly logged by clients, servers, proxies, analytics tools, and browser history. Even in a read-only IMDb plot-summary context, exposure of the token could allow unauthorized API use, quota theft, or access under the user's account.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This manifest-like JSON describes what the skill does but provides no narrow invocation conditions, trigger phrases, or exclusion conditions. In systems that infer skill activation from descriptions, broad descriptive text like this can increase the chance of unintended invocation because there is no explicit boundary for when the skill should or should not run.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest and operation metadata describe a plot-summary lookup, but the operation description adds analytics-oriented concepts like core metrics, trend signals, and performance indicators. This documentation contradicts the apparent purpose and endpoint naming, indicating copied or inaccurate intent documentation rather than the actual behavior of fetching a plot summary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.