Back to skill

Security audit

Instagram Reels Search API

Security checks for vulnerabilities and agentic risk

Overview

This skill does the advertised Instagram Reels search, but it handles the API token in a way that can leak it through command arguments and URL query logs.

Review this before installing if the JustOneAPI token has billing, quota, or broad account authority. Prefer a version that uses secure secret storage and an Authorization header, or use a short-lived, low-scope token and rotate it if it may have appeared in process lists or URL logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:22
Finding

API Credential Exposed Through URL Query Parameters and Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:22-31, bin/run.mjs:79-85, bin/run.mjs:99, bin/run.mjs:168-180, bin/run.mjs:223-233; documented invocation at SKILL.md:40
Vulnerability Type: Sensitive credential exposure
Risk Level: Medium

Vulnerable Code

js
{
  "defaultValue": null,
  "description": "Access token for the API service.",
  "enumValues": [],
  "location": "query",
  "name": "token",
  "required": true,
  "schemaType": "string"
}
js
const params = parseParams(args.paramsJson);
applyDefaults(operation, params);
injectToken(operation, params, args.token);
validateRequired(operation, params);

const baseUrl = manifest.baseUrl;
const url = new URL(operation.path, ensureBaseUrl(baseUrl));
applyPathParams(operation, params, url);
applyQueryParams(operation, params, url);
js
response = await fetch(url, requestInit);
js
function injectToken(operation, params, cliToken) {
  const tokenParam = operation.parameters.find((parameter) => parameter.name === "token");
  if (!tokenParam || params.token !== undefined) {
    return;
  }
  if (!cliToken) {
    fail("--token is required for this operation.", {
      operationId: operation.operationId,
    });
  }
  params.token = cliToken;
}
js
function applyQueryParams(operation, params, url) {
  for (const parameter of operation.parameters.filter((item) => item.location === "query")) {
    const value = params[parameter.name];
    if (value === undefined) {
      continue;
    }
    appendValue(url.searchParams, parameter.name, value);
  }
}

The documented invocation also supplies the secret through a command-line argument:

bash
node {baseDir}/bin/run.mjs --operation "searchReelsV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"keyword":"<keyword>"}'

Technical Analysis

The operation manifest classifies the AP ...[truncated 2752 chars]

Remediation
View remediation

Remediation Suggestions

  1. Change the API authentication scheme to use an HTTP authorization header, such as:

    js
    const requestInit = {
      headers: {
        "accept": "application/json",
        "authorization": `Bearer ${token}`,
      },
      method: operation.method,
    };
    
  2. Remove token from the operation’s query-parameter list so that applyQueryParams cannot append it to the URL.

  3. Read the credential directly from process.env.JUST_ONE_API_TOKEN rather than requiring it through --token. If CLI compatibility must be retained, prefer the environment variable and clearly deprecate the command-line option.

  4. Never include the token or complete authenticated URL in normal output, errors, debug logs, telemetry, or exception metadata.

  5. Disable automatic cross-origin redirects for authenticated requests, or explicitly verify that every redirect remains on the expected HTTPS origin before forwarding credentials.

  6. Configure API gateways, proxies, and server access logs to redact existing token query parameters while migration is in progress.

  7. Rotate credentials that may previously have appeared in process metadata or URL logs, and apply minimum API scopes, short expiration periods, quotas, and provider-side restrictions where supported.

  8. Update SKILL.md, generated/operations.json, and generated/operations.md to describe the safer authentication mechanism consistently.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This skill explicitly requests an access token as user-supplied input, creating credential-handling risk and normalizing direct exposure of secrets to the tool interface. In agent environments, such parameters can be surfaced in prompts, traces, or intermediate storage, enabling unintended disclosure or reuse of the credential.

Content

Scanner excerpt · generated/operations.json (reported line 15)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for the API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/run.mjs (reported line 20)May include surrounding context.

js
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for the API service. |
| `keyword` | `query` | yes | `string` | n/a | The search keyword or hashtag to filter Reels. |
| `paginationToken` | `query` | no | `string` | n/a | Token used for retrieving the next page of results. |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 19)May include surrounding context.

md
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for the API service. |
| `keyword` | `query` | yes | `string` | n/a | The search keyword or hashtag to filter Reels. |
| `paginationToken` | `query` | no | `string` | n/a | Token used for retrieving the next page of results. |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill defines the API access token as a query parameter and later appends all query parameters directly into the request URL. Query-string secrets are commonly exposed through logs, browser/history equivalents, proxies, monitoring systems, and error telemetry, making credential leakage more likely than if the token were sent in an Authorization header.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This is a manifest-style JSON file, so vague-trigger checks apply. The description states the skill should be used for Instagram Reels Search with a keyword, but it does not define specific invocation phrases, scope boundaries, or exclusion conditions, which can make activation criteria overly broad for generic 'search Instagram' requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The API requires a sensitive access token in the query string, which is commonly exposed through logs, browser history, proxy telemetry, analytics tools, and error traces. Even when sent over HTTPS, query parameters are more likely than headers to be retained or propagated by infrastructure, increasing the chance of credential leakage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.