Back to skill

Security audit

Instagram Post Details API

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but it should be reviewed because it places the JustOneAPI token in command arguments and URL query parameters where it may leak.

Install only if you are comfortable giving this skill a JustOneAPI token and making requests to api.justoneapi.com. Use a narrowly scoped, revocable token if possible, avoid shared machines and verbose command logging, and rotate the token if it may have appeared in process lists, logs, URLs, or diagnostics.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:62
Finding

API Token Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
"}' ``` The helper places that token into the parameter object and then appends all query parameters to the request URL: ```js const params = parseParams(args.paramsJson); applyDefaults(operation, params); injectToken(operation, params, args.token); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, }; ``` The command-line token is parsed and retained as a normal argument value: ```js function parseArgs(argv) { const parsed = { operation: null, paramsJson: "{}", token: null }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); } return parsed; } function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { ...[truncated 3330 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The API requires an access token as a query parameter, which is risky because query strings are commonly logged by clients, proxies, servers, and monitoring systems. Exposure of the token could allow unauthorized use of the API service and potential abuse of the associated account or quota.

Content

Scanner excerpt · generated/operations.json (reported line 15)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for the API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/run.mjs (reported line 20)May include surrounding context.

js
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for the API service. |
| `code` | `query` | yes | `string` | n/a | The unique shortcode (slug) for the Instagram post (e.g., 'DRhvwVLAHAG'). |

### Request body

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 19)May include surrounding context.

md
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for the API service. |
| `code` | `query` | yes | `string` | n/a | The unique shortcode (slug) for the Instagram post (e.g., 'DRhvwVLAHAG'). |

### Request body

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes a Node helper that performs an authenticated external API request, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates a transparency and policy-enforcement gap: a host may expose network-capable execution without users or runtime controls being clearly informed, increasing the risk of unintended outbound requests and token misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The operation explicitly supports retrieving and archiving Instagram post content and media assets, but the manifest provides no user-facing disclosure about data collection, storage, or privacy implications. In an agent setting, this can lead to users unknowingly authorizing access to third-party content or broader retention of media and metadata than they expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a manifest-style JSON file, so vague trigger guidance applies. The description explains what the API does but provides no explicit activation phrases, scope limits, or exclusion conditions, making invocation criteria ambiguous rather than narrowly defined.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents a required token query parameter but does not include any warning about protecting credentials or avoiding exposure in logs, URLs, or shared documentation. Because markdown files should warn about behaviours affecting privacy or system integrity, the omission is a quality/safety issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.