Back to skill

Security audit

Taobao and Tmall Shop Product List API

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it handles the API token in a way that can expose it through command lines and request URLs.

Review before installing. Use only a narrowly scoped, revocable JustOneAPI token, avoid running this in shared shells or logged CI jobs, and assume the token may appear in process listings or URL logs unless the provider and surrounding infrastructure redact it. This is a credential-handling review issue, not evidence of malware.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:305
Finding

API Token Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:305-308, bin/run.mjs:337-348, bin/run.mjs:389-402, and SKILL.md:52-60
Vulnerability Type: Credential exposure through command-line arguments and URL query parameters
Risk Level: Medium

Vulnerable Code

The documented invocation passes the secret as a command-line argument:

bash
node {baseDir}/bin/run.mjs --operation "getTaobaoShopItemListV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"userId":"<userId>"}'

The argument parser accepts and retains the token:

js
if (flag === "--token") {
  parsed.token = value;
  index += 1;
  continue;
}

The token is inserted into the general request parameter object:

js
function injectToken(operation, params, cliToken) {
  const tokenParam = operation.parameters.find((parameter) => parameter.name === "token");
  if (!tokenParam || params.token !== undefined) {
    return;
  }
  if (!cliToken) {
    fail("--token is required for this operation.", {
      operationId: operation.operationId,
    });
  }
  params.token = cliToken;
}

Because the manifest defines token as a query parameter, the generic query builder places the credential in the URL:

js
function applyQueryParams(operation, params, url) {
  for (const parameter of operation.parameters.filter((item) => item.location === "query")) {
    const value = params[parameter.name];
    if (value === undefined) {
      continue;
    }
    appendValue(url.searchParams, parameter.name, value);
  }
}

function appendValue(searchParams, name, value) {
  if (Array.isArray(value)) {
    for (const item of value) {
      appendValue(searchParams, name, item);
    }
    return;
  }
  if (value && typeof value === "object") {
    searchParams.append(name, JSON.stringify(value));
    return;
  }
  searchParams.append(name, String(value));
}

The resulting URL, including its token query parameter, is then transmitted:

js
response = await fetch(url, requestInit
...[truncated 2515 chars]
Remediation
View remediation

Remediation Suggestions

  1. Stop accepting secrets through command-line arguments.

    • Read JUST_ONE_API_TOKEN directly from process.env.
    • If an explicit alternate input mechanism is required, use protected standard input or a restricted credential file rather than an argument.
    • Remove --token from the documented command and argument parser.
  2. Prefer header-based authentication.

    • If JustOneAPI supports it, send the credential through an authorization header:
js
const token = process.env.JUST_ONE_API_TOKEN;
if (!token) {
  fail("JUST_ONE_API_TOKEN is required.");
}

const requestInit = {
  method: operation.method,
  headers: {
    accept: "application/json",
    authorization: `Bearer ${token}`,
  },
};
  1. Prevent alternate query-string injection.

    • Reject a token property supplied through --params-json.
    • Keep authentication data separate from ordinary operation parameters.
    • Do not process credentials through the generic applyQueryParams function.
  2. If the service requires query authentication, reduce residual exposure.

    • Document that the upstream protocol requires query-based credentials.
    • Configure API gateways, proxies, tracing systems, and application logs to redact the token parameter.
    • Never include the complete request URL in errors or diagnostics.
    • Use narrowly scoped, short-lived, and readily revocable tokens.
  3. Update documentation.

    • Replace the --token "$JUST_ONE_API_TOKEN" example with environment-based invocation.
    • Explain token rotation and revocation procedures.
    • Ensure documentation does not promise that tokens will never enter logs unless redaction is enforced across the request path.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This operation requires an access token as a query parameter, which is a risky pattern because query strings are commonly logged by clients, proxies, gateways, and server access logs. If the token is exposed through logs, browser history, monitoring tools, or referrer leakage, an attacker could reuse it to access the external API.

Content

Scanner excerpt · generated/operations.json (reported line 15)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for this API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This second API version repeats the same unsafe design by accepting the access token in the query string. The skill context increases risk because the token is sent to an external API service, making leakage through infrastructure logs or request tracing more plausible and potentially enabling unauthorized API use.

Content

Scanner excerpt · generated/operations.json (reported line 73)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for this API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Version 3 also places the access token in a query parameter, preserving the same credential-exposure weakness across all variants of the operation. Repetition across multiple endpoints broadens the attack surface and increases the chance of accidental disclosure through logs, telemetry, or debugging artifacts.

Content

Scanner excerpt · generated/operations.json (reported line 143)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for this API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/run.mjs (reported line 20)May include surrounding context.

js
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `userId` | `query` | yes | `string` | n/a | Shop identifier. Also known as Seller ID or User ID (they refer to the same value). |
| `sort` | `query` | no | `string` | `_sale` | Sort order for the result set.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/run.mjs (reported line 78)May include surrounding context.

js
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `userId` | `query` | yes | `string` | n/a | Shop identifier. Also known as Seller ID or User ID (they refer to the same value). |
| `sort` | `query` | no | `string` | `_sale` | Sort order for the result set.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/run.mjs (reported line 148)May include surrounding context.

js
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `userId` | `query` | yes | `string` | n/a | Shop identifier. Also known as Seller ID or User ID (they refer to the same value). |
| `sort` | `query` | no | `string` | `_sale` | Sort order for the result set.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 19)May include surrounding context.

md
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `userId` | `query` | yes | `string` | n/a | Shop identifier. Also known as Seller ID or User ID (they refer to the same value). |
| `sort` | `query` | no | `string` | `_sale` | Sort order for the result set.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 49)May include surrounding context.

md
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `userId` | `query` | yes | `string` | n/a | Shop identifier. Also known as Seller ID or User ID (they refer to the same value). |
| `sort` | `query` | no | `string` | `_sale` | Sort order for the result set.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 83)May include surrounding context.

md
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `userId` | `query` | yes | `string` | n/a | Shop identifier. Also known as Seller ID or User ID (they refer to the same value). |
| `sort` | `query` | no | `string` | `_sale` | Sort order for the result set.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs calling external API endpoints) but does not declare an explicit tool scope such as permissions or allowed-tools. This creates a policy gap where an agent or reviewer cannot easily constrain or reason about outbound network behavior, increasing the risk of unintended external requests or misuse if the skill is invoked in broader contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code sends the API token as a query parameter by appending all query parameters, including token, into the request URL. Tokens in URLs are routinely exposed through logs, browser/history mechanisms, intermediary proxies, monitoring systems, and error traces, so this creates unnecessary credential leakage risk even when HTTPS is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest explicitly routes requests to a third-party domain and requires transmission of an access token plus shop/user identifiers, but it does not disclose this data-sharing behavior or provide any warning/consent language. This creates a privacy and trust risk because users may unknowingly send sensitive operational identifiers and credentials to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The endpoint description states that the skill retrieves Taobao/Tmall shop product data for research and tracking, which implies transmission of userId/shopId and related query parameters to an external platform. The markdown does not disclose this privacy-relevant behavior to users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents a required token query parameter for the API but does not include any user-facing warning about transmitting credentials to an external service. For markdown files, SQP-2 applies when the description omits warnings about behaviors that could affect privacy or system integrity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.