Back to skill

Security audit

JD.com Shop Product List API

Security checks for vulnerabilities and agentic risk

Overview

This is a focused JD.com product-list API helper, but users should understand that its JustOneAPI token is passed on the command line and sent in the request URL query string.

Install only if you are comfortable sending a JustOneAPI token to api.justoneapi.com for this endpoint. Use a narrowly scoped token if available, avoid logging commands or full request URLs, and rotate the token if it may have appeared in process lists, shell history, monitoring, or URL logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:236
Finding

API Token Exposed Through Command-Line Arguments and URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:40,47; bin/run.mjs:18-27,62-68,141-145,236-251; generated/operations.json:15-24; generated/operations.md:19
Vulnerability Type: Credential exposure through process arguments and request URLs
Risk Level: Medium

The Skill legitimately requires a JustOneAPI access token to perform its declared JD.com product-list lookup. However, it passes the token through a command-line argument and subsequently places it in an HTTPS URL query parameter.

Relevant documented invocation:

bash
node {baseDir}/bin/run.mjs --operation "getJdShopItemListV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"shopId":"<shopId>"}'

Relevant parameter declaration:

js
{
  "defaultValue": null,
  "description": "Access token for this API service.",
  "enumValues": [],
  "location": "query",
  "name": "token",
  "required": true,
  "schemaType": "string"
}

Relevant token-processing and request-construction code:

js
const params = parseParams(args.paramsJson);
applyDefaults(operation, params);
injectToken(operation, params, args.token);
validateRequired(operation, params);

const baseUrl = manifest.baseUrl;
const url = new URL(operation.path, ensureBaseUrl(baseUrl));
applyPathParams(operation, params, url);
applyQueryParams(operation, params, url);
js
function injectToken(operation, params, cliToken) {
  const tokenParam = operation.parameters.find((parameter) => parameter.name === "token");
  if (!tokenParam || params.token !== undefined) {
    return;
  }
  if (!cliToken) {
    fail("--token is required for this operation.", {
      operationId: operation.operationId,
    });
  }
  params.token = cliToken;
}
js
function applyQueryParams(operation, params, url) {
  for (const parameter of operation.parameters.filter((item) => item.location === "query")) {
    const value = params[pa
...[truncated 3451 chars]
Remediation
View remediation

Remediation Suggestions

  1. Read JUST_ONE_API_TOKEN directly from process.env inside bin/run.mjs rather than requiring the token through --token. Remove or deprecate the command-line token option to prevent exposure through process listings and command telemetry.
  2. If supported by JustOneAPI, transmit the token in a dedicated authentication header, such as:
    js
    const requestInit = {
      method: operation.method,
      headers: {
        accept: "application/json",
        authorization: `Bearer ${process.env.JUST_ONE_API_TOKEN}`,
      },
    };
    
  3. Remove token from the operation's query-parameter definitions so generic query construction cannot accidentally append it to the URL.
  4. If the service contract mandates query authentication, document that limitation explicitly, ensure URLs are never logged, and configure reverse proxies, API gateways, monitoring systems, and server access logs to redact the token parameter.
  5. Add centralized redaction for sensitive field names such as token, authorization, and apiKey before writing errors or telemetry.
  6. Avoid printing constructed request URLs when handling failures. Add automated tests verifying that credentials do not appear in command lines, generated URLs, standard output, standard error, or diagnostic records.
  7. Rotate any token suspected of having been captured in process or URL logs and apply the narrowest available token permissions, quotas, and expiration period.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

This operation explicitly requests an access token, which constitutes credential material, and places it in a query parameter. In the context of a third-party API integration, this is more dangerous because the token may be exposed in logs, browser history, monitoring tools, or reused beyond the user's expectation, enabling unauthorized API access if intercepted.

Content

Scanner excerpt · generated/operations.json (reported line 15)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for this API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/run.mjs (reported line 20)May include surrounding context.

js
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `shopId` | `query` | yes | `string` | n/a | A unique shop identifier on JD.com (Shop ID). |
| `page` | `query` | no | `string` | n/a | Page number for paginated comments. |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 19)May include surrounding context.

md
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `shopId` | `query` | yes | `string` | n/a | A unique shop identifier on JD.com (Shop ID). |
| `page` | `query` | no | `string` | n/a | Page number for paginated comments. |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill invokes a network-capable helper (node .../run.mjs) and requires an API token, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where the agent/runtime may permit broader network use than reviewers or policy systems can verify, reducing containment and making misuse harder to detect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill defines the API access token as a query parameter and later appends all query parameters to the request URL, causing the credential to be transmitted in the URL. Query-string secrets are commonly exposed through logs, browser/history tooling, proxy infrastructure, monitoring systems, and error reports, so the token may leak even when HTTPS is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill requires an access token to be sent as a query parameter to an external service, yet the manifest provides no user-facing warning about credential transmission. Query parameters are more likely to be logged by intermediaries, client tooling, analytics systems, and server access logs, increasing the chance of token exposure or unintended credential handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This is a JSON manifest file, so vague-trigger checks apply. The top-level description explains what the skill does but provides no explicit trigger phrases, activation boundaries, or exclusion conditions, which can make it unclear when the skill should be invoked versus other shopping or product lookup skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.