Back to skill

Security audit

TikTok API

Security checks for vulnerabilities and agentic risk

Overview

This TikTok API skill is mostly coherent, but it handles the required API token in ways that can expose it through process arguments and request URLs.

Review before installing if you will use a paid or sensitive JustOneAPI token. Prefer running it in an environment where process arguments and request URLs are not logged, rotate the token if it may have appeared in logs, and only request TikTok profile, comment, reply, or search data when you have a legitimate reason and can handle the returned personal data appropriately.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:518
Finding

API Token Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
" --token "$JUST_ONE_API_TOKEN" --params-json '{"key":"value"}' ``` `bin/run.mjs:472-490`: ```javascript function parseArgs(argv) { const parsed = { operation: null, paramsJson: "{}", token: null }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } ``` `bin/run.mjs:518-528`: ```javascript function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` `bin/run.mjs:558-566`: ```javascript function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` `bin/run.mjs:431`: ```javascript response = await fetch(url, requestInit); ``` ### Technical Analysis The documented invocation expands `JUST_ONE_API_TOKEN` into the `--token` command-line argument. Depending on the ...[truncated 2735 chars]
Remediation
View remediation
" \ --params-json '{"key":"value"}' ``` The environment should preferably be provisioned by the execution environment rather than repeated inline. 2. **Use header-based authentication where supported** - Prefer an HTTP authorization header, such as: ```javascript const token = process.env.JUST_ONE_API_TOKEN; requestInit.headers.authorization = `Bearer ${token}`; ``` - Confirm the exact header and authentication scheme with JustOneAPI documentation before changing the client. 3. **Harden unavoidable query-parameter authentication** - If the service only supports a `token` query parameter, configure clients, gateways, proxies, application logs, tracing systems, and server access logs to redact it. - Never include the complete request URL in errors or diagnostics. - Disable URL capture in telemetry where redaction cannot be guaranteed. 4. **Validate credential presence securely** - Fail with a generic message if the environment variable is absent. - Do not print the token or the constructed authenticated URL to standard output or standard error. 5. **Reduce credential impact** - Use narrowly scoped tokens where supported. - Apply usage limits, expiration, rotation, and anomaly monitoring. - Revoke and replace any token suspected of appearing in process telemetry or URL logs. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
- Get a token from [Just One API Dashboard](https://dashboard.justoneapi.com/en/login?utm_source=clawhub.ai&utm_medium=referral&utm_campaign=justoneapi_tiktok&utm_content=project_link).
- Authentication details: [Just One API Usage Guide](https://docs.justoneapi.com/en/?utm_source=clawhub.ai&utm_medium=referral&utm_campaign=justoneapi_tiktok&utm_content=project_link).

## Output Rules

- Start with a plain-language answer tied to the TikTok task the user asked for.
- Include the most decision-relevant fields from the selected endpoint before dumping raw JSON.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a Node helper to make authenticated external API requests, but it does not declare an explicit tool scope such as allowed network access or command permissions. This creates an authorization and transparency gap: a host system or reviewer cannot easily constrain what the skill is permitted to do, increasing the risk of unintended external calls or misuse if the helper is modified or repurposed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says the skill analyzes TikTok workflows including user Published Posts, post Details, and user Profile across 7 operations, which implies those named data domains are the scope. However, the actual manifest/code exposes seven operations that also include post comments, comment replies, post search, and user search, materially expanding the skill beyond the stated description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill analyzes TikTok workflows including user Published Posts, post Details, and user Profile across 7 operations, which implies a narrower scope centered on those three data types. The actual operations also include Post Comments, Comment Replies, Post Search, and User Search (L8-L10, L91-L93, L251-L253, L334-L336), so the description does not accurately reflect the full behavior exposed by the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Passing API security tokens in query parameters is dangerous because URLs are commonly logged by clients, servers, proxies, analytics tools, and error monitoring systems. Even when HTTPS is used, the token may still be exposed through logs, browser history, shared traces, or downstream observability tooling, increasing the risk of credential leakage and unauthorized API use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill covers 'user Published Posts, post Details, and user Profile across 7 operations,' which implies a narrower scope centered on three resource types. However, the operations file also exposes post comments, comment replies, post search, and user search endpoints, which are materially broader capabilities than the description states.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly enables collection of profile, comment, and reply data for analysis but provides no privacy, retention, consent, or handling guidance. In a social-data collection context, this increases the risk of over-collection, misuse of personal data, and noncompliant downstream processing by agents or users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest sets the region parameter default to US, which imposes a locale-specific behavior by default. There is no accompanying justification that this skill is US-specific, nor language indicating that users can choose or override the locale intentionally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The parameter documentation sets region to US as the default, which imposes a locale-specific behavior without indicating user opt-in or a documented region-specific justification. SQP-3 covers language or locale policy violations in natural-language/config-style content across all file types.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.