Back to skill

Security audit

Web Page HTML Content API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent JustOneAPI helper for fetching web page HTML, with disclosed token and URL inputs, but users should be careful because the API token is placed in a query string and submitted URLs go to a third-party service.

Install only if you are comfortable sending requested URLs and fetched page content to JustOneAPI. Use a scoped or disposable JustOneAPI token if possible, avoid submitting private or internal URLs, and remember that query-string tokens may appear in logs or process metadata.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:19
Finding

API Credential Exposed Through Command-Line Arguments and URL Query Parameters

Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` All parameters designated as query parameters, including the token, are appended to the request URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The documentation additionally directs users to supply the token as a command-line argument: ```bash node {baseDir}/bin/run.mjs --operation "htmlV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"url":""}' ``` ### Technical Analysis The Skill requires an API token for its declared operation, so transmitting an authentication credential to JustOneAPI is functionally necessary. However, placing the credential in the URL query string exceeds the minimum exposure necessary for authentication. After `injectToken` assigns the command-line token to `params.token`, `applyQue ...[truncated 2552 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill invokes a network-capable helper (node .../run.mjs) that can make outbound requests, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes it easier for the skill to perform network access without clear review boundaries, especially since the user-supplied url determines the fetch target.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill requires the API token to be sent as a query parameter, which is unsafe because query strings are commonly logged by clients, proxies, analytics systems, browser history, and server infrastructure. Even though the destination uses HTTPS, placing secrets in the URL materially increases the chance of credential leakage beyond the immediate transport channel.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill forwards a user-supplied URL to an external third-party API that fetches the page content, which exposes potentially sensitive browsing targets or internal URLs to that provider without any warning in the code. In context, this is the core function of the skill rather than hidden exfiltration, but it still creates privacy and data-handling risk, especially if users submit private, authenticated, or internal-only URLs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest states that arbitrary web page HTML is sent to an external API service but does not warn users that requested URLs and fetched content will transit a third-party provider. This creates privacy and compliance risk because users or agents may submit sensitive URLs or internal resources without understanding the network exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill exposes a generic URL-fetching capability with no stated scope restrictions, allowlist, or trigger constraints. In an agent context, this can enable overly broad external requests, including retrieval of sensitive or attacker-chosen pages, increasing SSRF-like misuse, data exfiltration, and unsafe browsing risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation describes a capability that sends a user-supplied URL together with an authentication token to an external third-party API, but it does not warn users about that data flow or associated privacy and trust implications. This can mislead users into providing sensitive internal URLs or tokens without understanding they are being transmitted off-platform, increasing the risk of unintended data disclosure.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:41