Back to skill

Security audit

Toutiao Article Details API

Security checks for vulnerabilities and agentic risk

Overview

This skill is narrowly aimed at fetching Toutiao article details from JustOneAPI, but it handles the required API token in ways that can expose it through command-line arguments and URL logs.

Review before installing if the JustOneAPI token has billing impact, broad access, or long validity. Prefer a narrowly scoped, revocable token, avoid command logging or shell tracing, and rotate the token if it may have appeared in process lists, logs, URLs, or telemetry.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:224
Finding

API Authentication Token Transmitted in the URL Query String

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:73-75 and bin/run.mjs:224-231
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

js
injectToken(operation, params, args.token);
validateRequired(operation, params);

const baseUrl = manifest.baseUrl;
const url = new URL(operation.path, ensureBaseUrl(baseUrl));
applyPathParams(operation, params, url);
applyQueryParams(operation, params, url);
js
function appendValue(searchParams, name, value) {
  if (Array.isArray(value)) {
    for (const item of value) {
      appendValue(searchParams, name, item);
    }
    return;
  }
  if (value && typeof value === "object") {
    searchParams.append(name, JSON.stringify(value));
    return;
  }
  searchParams.append(name, String(value));
}

The operation manifest defines the authentication token as a required query parameter:

js
{
  "description": "Authentication token required to access the API.",
  "enumValues": [],
  "location": "query",
  "name": "token",
  "required": true,
  "schemaType": "string"
}

Technical Analysis

The helper injects the supplied authentication token into the general parameter object. Because the manifest marks token as a query parameter, applyQueryParams ultimately appends it to the request URL.

HTTPS protects the URL against passive observation while it is in transit, and the code restricts requests to the declared https://api.justoneapi.com destination. Nevertheless, query strings are commonly recorded by API gateways, reverse proxies, server access logs, monitoring products, error reports, and diagnostic tooling. Placing reusable credentials in a URL therefore creates broader and longer-lived exposure than transmitting them in an authorization header.

Sending an authentication credential to JustOneAPI is necessary for the declared functionality ...[truncated 1109 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer an HTTP authorization header rather than a query parameter:
    js
    requestInit.headers.authorization = `Bearer ${token}`;
    
  2. Remove token from the URL parameter manifest and keep it separate from ordinary endpoint parameters.
  3. If JustOneAPI only supports query-based authentication, coordinate an API change to support header-based credentials.
  4. Until header authentication is available, configure clients, gateways, reverse proxies, monitoring systems, and server logs to redact the token query parameter.
  5. Use narrowly scoped, short-lived, and readily revocable tokens to limit the consequences of disclosure.
  6. Ensure exception handling and diagnostics never emit the complete request URL.

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:148
Finding

Authentication Token Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:38 and bin/run.mjs:148-152
Vulnerability Type: Credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

The documented invocation expands the secret environment variable into a command-line argument:

bash
node {baseDir}/bin/run.mjs --operation "getToutiaoArticleDetailV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"id":"<id>"}'

The executable parses the secret directly from the process argument vector:

js
if (flag === "--token") {
  parsed.token = value;
  index += 1;
  continue;
}

Technical Analysis

Although the token originates in the JUST_ONE_API_TOKEN environment variable, the documented command expands it into the Node.js process argument vector. Command-line arguments may be observable through process inspection facilities, execution auditing, endpoint telemetry, orchestration metadata, shell tracing, debugging tools, or wrapper error reports.

The exact exposure depends on operating-system process isolation and the permissions of local observers. However, passing a secret through argv unnecessarily increases its visibility because the executable can read the already-required environment variable directly.

Attack Path

  1. A user or agent follows the documented command.
  2. The shell expands $JUST_ONE_API_TOKEN before starting Node.js.
  3. The plaintext token becomes part of the process argument vector.
  4. A sufficiently privileged local process, process-monitoring service, audit collector, or diagnostic wrapper captures the arguments.
  5. An attacker with access to that captured data obtains the token.
  6. The attacker reuses the token against JustOneAPI within its assigned scope.

Impact Assessment

Exposure permits unauthorized use of the affected JustOneAPI account to the extent allowed by the token. This may result in unauthorized API access, quota depletion, bil ...[truncated 357 chars]

Remediation
View remediation

Remediation Suggestions

  1. Read the credential directly from the declared environment variable:
    js
    const token = process.env.JUST_ONE_API_TOKEN;
    
  2. Remove --token from the documented command and use:
    bash
    node {baseDir}/bin/run.mjs --operation "getToutiaoArticleDetailV1" --params-json '{"id":"<id>"}'
    
  3. Keep token values out of command strings, shell history, tracing output, process titles, and execution telemetry.
  4. If multiple credential sources are required, support secure environment variables or protected file descriptors rather than plaintext command-line options.
  5. Use least-privilege, short-lived tokens and provide a documented revocation and rotation procedure.
  6. Add automated tests confirming that neither stdout nor stderr contains the credential during successful and failed requests.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a Node-based helper that performs outbound API calls using a bearer token, but the manifest does not declare an explicit tool scope such as allowed network access or permissions. This weakens least-privilege controls and makes it harder for a host platform to enforce or audit what external access the skill is supposed to have, increasing the risk of unintended or abused network operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Passing an authentication token as a query parameter is risky because query strings are commonly logged by servers, intermediaries, browser history, observability tools, and proxies. Even though this endpoint appears read-only, exposing the token can enable unauthorized API access if the credential is reused or remains valid.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This is a manifest-style JSON file, so vague-trigger checks apply. The description only says to call the endpoint for article details and content analysis/media monitoring, but it does not provide specific trigger phrases, activation boundaries, or negative examples to distinguish appropriate use from general requests about articles.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:41