Back to skill

Security audit

Weibo Keyword Search API

Security checks for vulnerabilities and agentic risk

Overview

This is a narrowly scoped Weibo search API wrapper, with a real but disclosed token-handling risk users should understand.

Install only if you are comfortable sending Weibo search terms and your JustOneAPI token to api.justoneapi.com. Use a dedicated, least-privileged token if possible, avoid logging commands or full URLs, and rotate the token if it may have appeared in process logs, shell traces, monitoring, or API logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:19
Finding

API Token Exposed Through Command-Line Arguments and URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:19-24, 138-158, 207-217, 243-255, 288-310; SKILL.md:49, 57
Vulnerability Type: API credential exposure
Risk Level: Medium

The API token is accepted through the --token command-line argument and subsequently inserted into the request URL as a query parameter.

Vulnerable Code

bin/run.mjs:19-24 defines the credential as a query parameter:

js
      {
        "defaultValue": null,
        "description": "API access token.",
        "enumValues": [],
        "location": "query",
        "name": "token",
        "required": true,
        "schemaType": "string"
      },

bin/run.mjs:138-158 constructs the URL, adds all query parameters, and sends it:

js
const baseUrl = manifest.baseUrl;
const url = new URL(operation.path, ensureBaseUrl(baseUrl));
applyPathParams(operation, params, url);
applyQueryParams(operation, params, url);

const requestInit = {
  headers: {
    "accept": "application/json",
  },
  method: operation.method,
};

if (operation.requestBody && params.body !== undefined) {
  requestInit.body = JSON.stringify(params.body);
  requestInit.headers["content-type"] = operation.requestBody.contentType || "application/json";
}

let response;
try {
  response = await fetch(url, requestInit);

bin/run.mjs:207-217 reads the token from the command line:

js
    if (flag === "--params-json") {
      parsed.paramsJson = value;
      index += 1;
      continue;
    }
    if (flag === "--token") {
      parsed.token = value;
      index += 1;
      continue;
    }
    fail(`Unknown argument "${flag}".`);

bin/run.mjs:243-255 places that token into the parameter collection:

js
function injectToken(operation, params, cliToken) {
  const tokenParam = operation.parameters.find((parameter) => parameter.name === "token");
  if (!tokenParam || params.toke
...[truncated 4141 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove command-line token handling. Read the token directly from process.env.JUST_ONE_API_TOKEN so it is not included in the process argument vector:

    js
    const token = process.env.JUST_ONE_API_TOKEN;
    if (!token) {
      fail("JUST_ONE_API_TOKEN is required.", {
        operationId: operation.operationId,
      });
    }
    
  2. Use an authorization header if the upstream API supports it. Remove token from query-parameter serialization and send it through a dedicated header:

    js
    const requestInit = {
      headers: {
        accept: "application/json",
        authorization: `Bearer ${token}`,
      },
      method: operation.method,
    };
    
  3. If query authentication is an unavoidable upstream requirement:

    • Continue reading the token from the environment rather than --token.
    • Build redacted URL representations for logging and diagnostics.
    • Never include the complete request URL in errors, traces, or telemetry.
    • Configure gateways, proxies, and server access logs to redact the token parameter.
    • Document that query-string authentication remains a residual exposure risk.
    • Use short-lived, narrowly scoped tokens where supported.
  4. Prevent accidental alternate injection. Reject token inside --params-json rather than allowing it to bypass the intended credential source.

  5. Update documentation. Replace the command in SKILL.md with one that relies on the inherited environment variable and does not include --token.

  6. Rotate exposed credentials. After deploying the safer authentication flow, revoke and replace tokens previously used with the command-line/query-string implementation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill requires an API access token to be sent as a query parameter, which is an insecure credential-handling pattern. Query-string credentials are commonly exposed in logs, browser history, proxy caches, monitoring tools, referrer headers, and error reports, increasing the chance of token leakage and unauthorized API access.

Content

Scanner excerpt · generated/operations.json (reported line 15)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "API access token.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/run.mjs (reported line 20)May include surrounding context.

js
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | API access token. |
| `q` | `query` | yes | `string` | n/a | Search Keywords. |
| `startDay` | `query` | yes | `string` | n/a | Start Day (yyyy-MM-dd). |
| `startHour` | `query` | yes | `integer` | n/a | Start Hour (0-23). |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 19)May include surrounding context.

md
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | API access token. |
| `q` | `query` | yes | `string` | n/a | Search Keywords. |
| `startDay` | `query` | yes | `string` | n/a | Start Day (yyyy-MM-dd). |
| `startHour` | `query` | yes | `integer` | n/a | Start Hour (0-23). |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a Node helper that performs outbound API requests using a bearer token, but the manifest does not declare any explicit tool scope such as allowed-tools or permissions. This creates a transparency and governance gap: the runtime can access the network despite the skill not advertising that capability, which can enable unintended data exfiltration or execution of external requests without clear user/operator approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill defines the API access token as a query parameter, which causes the credential to be placed in the URL. Query strings are commonly logged by clients, proxies, gateways, browser history, and server access logs, making accidental credential exposure significantly more likely even when HTTPS is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill sends user-supplied search parameters and the token to a third-party endpoint without any explicit user-facing disclosure or consent boundary. In this context the network call is expected functionality, but it still creates a data exposure risk because both the credential and potentially sensitive search terms leave the local environment and may be retained by the external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents an API access token as a required query parameter, which exposes credentials in URLs. Query strings are commonly logged by clients, proxies, browser history, analytics systems, and server access logs, so using tokens this way increases the chance of accidental credential disclosure even if HTTPS is used.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:49