Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Creator Core Metrics API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a narrow JustOneAPI wrapper, but its API token handling can expose the token through command-line arguments and URL query logs.

Review before installing if the JustOneAPI token has meaningful account access or billing impact. Use a narrowly scoped token if possible, avoid shell tracing or logging command lines, do not share full request URLs or errors that may contain query strings, and rotate the token if it may have appeared in logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:128
Finding

API Token Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } function appendValue(searchPar ...[truncated 3517 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and relies on an API token, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch weakens policy enforcement and reviewability: an agent platform may permit networked execution without a clear, least-privilege declaration, increasing the chance of unintended external requests or token use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill requires the authentication token to be supplied as a query parameter and then appends it to the request URL. Query-string credentials are commonly exposed in logs, browser/history tooling, reverse proxies, monitoring systems, and error messages, making accidental credential disclosure more likely even when HTTPS is used. In this skill context, the danger is higher because the token is the primary secret for accessing a third-party API and the code provides no warning to users about this handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The API specification requires an authentication token to be sent as a URL query parameter, which is a well-known insecure pattern because query strings are commonly logged by servers, proxies, analytics systems, browser history, and monitoring tools. Even if HTTPS is used, the token can still leak through operational logs or shared URLs, enabling unauthorized API access if exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file describes a token query parameter used for user authentication, which is sensitive credential material. The document does not include any warning about protecting the token, avoiding logging/sharing it, or the privacy implications of sending it in requests.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:49