Back to skill

Security audit

Taobao and Tmall Product Reviews API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow JustOneAPI wrapper for Taobao/Tmall review lookup, with a real but disclosed credential-handling caution around passing the API token in command arguments and URL query parameters.

Install only if you are comfortable giving this skill a JustOneAPI token for Taobao/Tmall review lookups. Prefer a narrowly scoped or disposable token, avoid sharing command logs, and rotate the token if you suspect process arguments or request URLs were logged.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:226
Finding

API Token Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` All query parameters, including the token, are added to the URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.sea ...[truncated 2399 chars]
Remediation
View remediation
`, if supported by JustOneAPI. 3. If the external API contract strictly requires a query token: - Avoid logging the complete request URL. - Configure gateways, proxies, monitoring systems, and error handlers to redact the `token` parameter. - Use short-lived, narrowly scoped tokens. - Rotate the token immediately after suspected exposure. 4. Reject `token` inside `--params-json` so callers cannot bypass the safer credential source. 5. Update `SKILL.md` to instruct users to set `JUST_ONE_API_TOKEN` without expanding it into the command line. 6. Ensure backend errors and diagnostics never include the complete request URL or authentication value. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The skill requires an API access token and transmits it as a URL query parameter. Query parameters are commonly logged by client tooling, proxies, gateways, browser history, and server access logs, so the credential can be exposed beyond its intended destination. In this skill context, the token is the primary secret used to authorize access to the third-party API, which makes accidental leakage materially dangerous even though the code does not appear intentionally malicious.

Content

Scanner excerpt · bin/run.mjs (reported line 20)May include surrounding context.

js
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for this API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.json (reported line 15)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for this API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 19)May include surrounding context.

md
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for this API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Passing an access token in a query parameter is unsafe because query strings are commonly logged by clients, servers, proxies, analytics systems, and browser history. Even over HTTPS, token exposure through logs or downstream telemetry can lead to credential leakage and unauthorized API access.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This is a JSON manifest file, so vague-trigger review applies. The description and display name describe the capability broadly but provide no explicit invocation scope, exclusions, or negative examples, which can make routing ambiguous when a user asks generally about product reviews or research.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.