Back to skill

Security audit

IMDb Top Cast and Crew API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow IMDb API helper, but it sends the user's JustOneAPI token in the URL query string, which can expose the credential in logs or telemetry.

Review before installing if the JustOneAPI token has broad account access, billing impact, or long lifetime. Use a limited or disposable token if available, avoid sharing command logs, and rotate the token if you suspect request URLs may have been logged.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:27
Finding

API Credential Exposed in URL Query String

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:27-34, bin/run.mjs:106-107, and bin/run.mjs:242-250
Vulnerability Type: API credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

js
{
  "defaultValue": null,
  "description": "User's authentication token.",
  "enumValues": [],
  "location": "query",
  "name": "token",
  "required": true,
  "schemaType": "string"
}
js
applyPathParams(operation, params, url);
applyQueryParams(operation, params, url);
js
function applyQueryParams(operation, params, url) {
  for (const parameter of operation.parameters.filter((item) => item.location === "query")) {
    const value = params[parameter.name];
    if (value === undefined) {
      continue;
    }
    appendValue(url.searchParams, parameter.name, value);
  }
}

Technical Analysis

The manifest classifies the authentication token as a query parameter. After injectToken() places the supplied credential in params.token, applyQueryParams() serializes it into the request URL before fetch() sends the request to the declared JustOneAPI HTTPS endpoint.

HTTPS protects the request from passive network interception, but it does not prevent the full URL from being retained by systems that terminate or process the request. Query strings can appear in destination-server access logs, reverse-proxy logs, API gateway telemetry, monitoring systems, diagnostic traces, and error reports. This creates unnecessary credential exposure compared with sending the token in an authorization header.

The documented invocation also passes the token through the --token command-line argument. Although the shell expands an environment variable rather than hard-coding the secret, the resulting credential may be visible transiently through local process inspection or command auditing.

The outbound network request is necessary for the Skill's declared API functionality, and the destination matches the documented ...[truncated 1556 chars]

Remediation
View remediation

Remediation Suggestions

  1. Change the authentication contract to transmit the token in an HTTP authorization header, preferably:

    js
    const requestInit = {
      headers: {
        "accept": "application/json",
        "authorization": `Bearer ${token}`,
      },
      method: operation.method,
    };
    
  2. Remove token from operation.parameters so it cannot be serialized into url.searchParams.

  3. Read the token directly from process.env.JUST_ONE_API_TOKEN rather than requiring it through --token, reducing exposure through process arguments:

    js
    const token = process.env.JUST_ONE_API_TOKEN;
    
  4. Ensure application errors, traces, and telemetry redact authorization headers and any parameter named token.

  5. Update SKILL.md, generated/operations.json, and generated/operations.md to document the corrected authentication mechanism.

  6. If the upstream service only supports query-string authentication:

    • Clearly document the residual credential-logging risk.
    • Configure reverse proxies, gateways, servers, and monitoring systems to redact the token parameter.
    • Avoid logging complete request URLs.
    • Use short-lived, narrowly scoped tokens where supported.
    • Rotate any token suspected of appearing in logs.
    • Restrict access to existing logs and establish retention limits.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill requires an authentication token to be provided as a query parameter, even though its stated purpose is only to retrieve IMDb cast and crew data. Query parameters are commonly logged by clients, proxies, gateways, and servers, which increases the chance of credential leakage and unnecessarily gives the skill access to sensitive credential-handling behavior beyond its narrow function.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Sending a required authentication token in the URL query string is unsafe because URLs are frequently recorded in browser history, telemetry, reverse proxies, and application logs. The lack of any warning or disclosure increases the likelihood that users will expose a reusable secret without understanding the risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.