Back to skill

Security audit

Kuaishou User Published Videos API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a focused JustOneAPI wrapper, but it passes the API token through the command line and URL query string where it may be exposed in logs or process metadata.

Review this skill before installing if your JustOneAPI token has broad account access, paid quota, or sensitive data access. Use narrowly scoped or disposable tokens if available, avoid sharing command output or process listings, and rotate the token if you suspect it appeared in logs. The inspected artifacts do not show persistence, local credential scraping, or calls to undeclared hosts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:67
Finding

API Token Exposed Through URL Query Parameters

Content
View full analysis
item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } function appendValue(searchParams, name, value) { if (Array.isArray(value)) { for (const item of value) { appendValue(searchParams, name, item); } return; } if (value && typeof value === "object") { searchParams.append(name, JSON.stringify(value)); return; } searchParams.append(name, String(value)); } ``` The documented invocation also supp ...[truncated 3141 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The operation requires an access token to be supplied as a query parameter, which is a sensitive credential handling pattern. Query-string tokens are more likely to be exposed through logs, browser history, proxy caches, referrer headers, and monitoring systems, increasing the risk of credential leakage and unauthorized API use.

Content

Scanner excerpt · generated/operations.json (reported line 15)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for this API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/run.mjs (reported line 20)May include surrounding context.

js
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `userId` | `query` | yes | `string` | n/a | The unique user ID on Kuaishou. |
| `pcursor` | `query` | no | `string` | n/a | Pagination cursor for subsequent pages. |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 19)May include surrounding context.

md
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `userId` | `query` | yes | `string` | n/a | The unique user ID on Kuaishou. |
| `pcursor` | `query` | no | `string` | n/a | Pagination cursor for subsequent pages. |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and requires an API token, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch weakens policy enforcement and reviewability: a host agent may permit broader execution or fail to clearly constrain when network access is allowed, increasing the risk of unintended outbound requests with sensitive parameters or credentials.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This manifest-style file describes what the skill does but provides no explicit invocation constraints, trigger phrases, or exclusion conditions. In systems that use descriptions to route skills, broad wording like calling the API 'with userId' for 'creator monitoring and content performance analysis' can be too open-ended and increase the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
67% confidence
Finding

The skill is hard-wired in its natural-language description to the Kuaishou platform and does not indicate any user choice or documented justification for this locale/platform restriction. Because policy violations here are limited to language or locale constraints, this is only a weak signal, but the file presents a fixed context without opt-in language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.