Back to skill

Security audit

IMDb Redux Overview API

Security checks for vulnerabilities and agentic risk

Overview

This is a focused IMDb lookup skill that calls one declared JustOneAPI endpoint, with a credential-handling risk users should understand.

Before installing, understand that this skill uses your JustOneAPI token to make IMDb overview requests. The main risk is token exposure through local process arguments or URL logs because the reviewed API flow uses a query-string token; use a scoped or low-privilege token if available, avoid sharing command logs, and rotate the token if you suspect it was exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:89
Finding

API Token Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
"}' ``` The command-line parser reads the token: ```js function parseArgs(argv) { const parsed = { operation: null, paramsJson: "{}", token: null }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); } return parsed; } ``` The token is injected into the ordinary parameter object: ```js function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` Because the manifest defines ` ...[truncated 4214 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) that makes authenticated external API requests, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates a mismatch between declared and actual capabilities, reducing transparency and weakening policy enforcement or review controls around outbound network use and secret handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Passing an authentication token in the query string is unsafe because query parameters are commonly recorded in logs, browser history, analytics systems, proxies, and monitoring tools. Even over HTTPS, the token may be exposed to intermediaries or operational logging, increasing the risk of credential leakage and unauthorized API use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API documentation instructs clients to send the authentication token as a query parameter, which causes the credential to be embedded in URLs. Query-string secrets are commonly exposed via browser history, server and proxy logs, analytics tooling, referrer headers, and monitoring systems, increasing the chance of token disclosure even when HTTPS is used.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This JSON file describes the skill in broad natural language but does not specify any explicit trigger phrases, activation boundaries, or exclusion conditions. For manifest files, that can make it unclear when the skill should activate versus when a general movie-information request should map elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.