Back to skill

Security audit

Instagram User Profile API

Security checks for vulnerabilities and agentic risk

Overview

The skill has a narrow Instagram profile lookup purpose, but it handles the API token through command-line arguments and URL query parameters, which can expose the credential in logs or process records.

Review this before installing if your JustOneAPI token has meaningful quota, billing, or account access. Use a low-scope token if possible, avoid running it where command lines or full URLs are logged, and rotate the token if it appears in shell history, process telemetry, proxy logs, or error reports.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:24
Finding

API Token Exposed Through Command-Line Arguments and URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:39-44; bin/run.mjs:24-31, 65-71, 196-206
Vulnerability Type: API credential exposure through process arguments and URL query parameters
Risk Level: Medium

Vulnerable Code

SKILL.md:39-44:

bash
node {baseDir}/bin/run.mjs --operation "getInstagramUserDetailV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"username":"<username>"}'
markdown
- Required: `JUST_ONE_API_TOKEN`
- Pass the token with `--token "$JUST_ONE_API_TOKEN"`; do not paste token values into chat messages, screenshots, or logs.

bin/run.mjs:24-31:

javascript
{
  "defaultValue": null,
  "description": "Access token for the API service.",
  "enumValues": [],
  "location": "query",
  "name": "token",
  "required": true,
  "schemaType": "string"
}

bin/run.mjs:65-71:

javascript
const params = parseParams(args.paramsJson);
applyDefaults(operation, params);
injectToken(operation, params, args.token);
validateRequired(operation, params);

const baseUrl = manifest.baseUrl;
const url = new URL(operation.path, ensureBaseUrl(baseUrl));
applyPathParams(operation, params, url);
applyQueryParams(operation, params, url);

bin/run.mjs:196-206:

javascript
function applyQueryParams(operation, params, url) {
  for (const parameter of operation.parameters.filter((item) => item.location === "query")) {
    const value = params[parameter.name];
    if (value === undefined) {
      continue;
    }
    appendValue(url.searchParams, parameter.name, value);
  }
}

Technical Analysis

The documented invocation passes JUST_ONE_API_TOKEN through the --token command-line option. Command-line arguments can be exposed to local process-inspection facilities, execution telemetry, shell tracing, diagnostic tooling, and CI/CD logs.

The helper subsequently injects the token into the parameters and serializes all query-located parameters into the request URL. The resulting request therefore includes the credent ...[truncated 1978 chars]

Remediation
View remediation

Remediation Suggestions

  1. Read the token directly from process.env.JUST_ONE_API_TOKEN rather than requiring it as a command-line argument.
  2. Remove or deprecate --token to prevent credentials from appearing in process listings and command logs.
  3. Send the credential in an Authorization header if JustOneAPI supports header-based authentication:
javascript
const token = process.env.JUST_ONE_API_TOKEN;
if (!token) {
  fail("JUST_ONE_API_TOKEN is required.");
}

const requestInit = {
  method: operation.method,
  headers: {
    accept: "application/json",
    authorization: `Bearer ${token}`,
  },
};
  1. Remove token from query-parameter serialization when header authentication is available.
  2. Reject token inside --params-json so credentials have one controlled input path.
  3. If the upstream service only supports query authentication, document the residual exposure and configure clients, proxies, gateways, servers, monitoring systems, and error reporters to redact the token query parameter.
  4. Ensure error messages never include the complete request URL or credential.
  5. Rotate any token suspected of having appeared in process telemetry, shell history, CI logs, proxy logs, or server access logs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

This operation explicitly collects an access token, which is a sensitive credential, and transmits it to a third-party service. In this context the capability is expected for API authentication, but it remains dangerous because compromise, logging exposure, or misuse of the token could grant unauthorized access to the user's API account or billable resources.

Content

Scanner excerpt · generated/operations.json (reported line 15)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for the API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/run.mjs (reported line 20)May include surrounding context.

js
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for the API service. |
| `username` | `query` | yes | `string` | n/a | The Instagram username whose profile details are to be retrieved. |

### Request body

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 19)May include surrounding context.

md
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for the API service. |
| `username` | `query` | yes | `string` | n/a | The Instagram username whose profile details are to be retrieved. |

### Request body

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a Node-based helper that performs outbound API calls using a secret token, but it does not declare any explicit tool scope such as allowed-tools or permissions. This creates a policy gap: an agent or reviewer cannot clearly constrain or verify the network capability from the manifest alone, increasing the risk of unintended external requests or misuse of the provided token.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code appends all query parameters directly to the request URL, and this operation defines the API token as a query parameter. Secrets placed in URLs can be exposed through logs, browser/history tooling, proxy logs, monitoring systems, and error messages, making credential leakage more likely even when HTTPS is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill requires an API access token to be sent as a query parameter, but the definition provides no user-facing disclosure about credential handling, storage, or transmission risks. Query parameters are commonly exposed in logs, traces, browser history, intermediary monitoring, and analytics systems, increasing the chance of credential leakage beyond the intended recipient.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends both an API access token and a target username to an external third-party service, but the documentation provides no warning to users or operators about that transmission. This creates a privacy and credential-handling risk because sensitive authentication material and queried identifiers may be exposed to or logged by the external provider without informed consent or clear handling expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This manifest-style JSON describes the skill in broad natural language without any explicit trigger phrases, scope limits, or exclusion conditions. For systems that infer invocation from descriptions, phrases like retrieving an Instagram user profile by username are generic enough that the skill could be matched in unintended contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file describes an operation but does not specify how or when it should be invoked, nor does it provide any constraints or exclusion conditions. For markdown files, missing specificity around activation scope can lead to overly broad or unintended use if this document is used as a skill description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.