Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Creator Profile API

Security checks for vulnerabilities and agentic risk

Overview

This skill is narrowly focused on one JustOneAPI creator-profile lookup, but it handles the user's API token in ways that can expose it through URLs and process arguments.

Review this before installing if you are sensitive to API-token leakage. Use a narrowly scoped, revocable JustOneAPI token, avoid sharing command logs or process telemetry, and rotate the token if you suspect URLs or command arguments were captured.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:22
Finding

API Token Transmitted in the URL Query String

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:22-30, bin/run.mjs:83-85, bin/run.mjs:205-212
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

js
{
  "defaultValue": null,
  "description": "User authentication token.",
  "enumValues": [],
  "location": "query",
  "name": "token",
  "required": true,
  "schemaType": "string"
}
js
const url = new URL(operation.path, ensureBaseUrl(baseUrl));
applyPathParams(operation, params, url);
applyQueryParams(operation, params, url);
js
function appendValue(searchParams, name, value) {
  if (Array.isArray(value)) {
    for (const item of value) {
      appendValue(searchParams, name, item);
    }
    return;
  }
  if (value && typeof value === "object") {
    searchParams.append(name, JSON.stringify(value));
    return;
  }
  searchParams.append(name, String(value));
}

Technical Analysis

The authentication token is declared as a query parameter. After injectToken() places the credential in params.token, applyQueryParams() passes it to appendValue(), which adds it to the URL. The resulting request therefore contains the credential in a form equivalent to:

text
https://api.justoneapi.com/api/.../v1?token=REDACTED&userId=USER_ID

HTTPS protects the URL while it is in transit, but it does not prevent the complete URL from being recorded by the destination service, API gateways, reverse proxies, observability systems, network diagnostics, or error-reporting infrastructure. Query-string credentials are consequently more likely to leak into retained logs than credentials sent through an authentication header.

The destination is hard-coded to the declared https://api.justoneapi.com service, and the token is required to use that service. This is therefore not evidence of covert exfiltration or an unauthorized de ...[truncated 1192 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace query-string authentication with a provider-supported authentication header, preferably:

    js
    const requestInit = {
      headers: {
        accept: "application/json",
        authorization: `Bearer ${token}`,
      },
      method: operation.method,
    };
    
  2. Remove token from the operation's ordinary query parameters so it cannot be appended to the URL accidentally.

  3. If JustOneAPI supports another dedicated authentication header, use that header according to its official specification.

  4. Configure application, gateway, proxy, monitoring, and error-reporting systems to redact authorization credentials and sensitive query parameters.

  5. If the upstream API exclusively requires query authentication, use short-lived, narrowly scoped tokens and explicitly document the residual URL-logging risk.

  6. Implement prompt token revocation and rotation procedures for suspected exposure.

T09 · Insecure Skill Coding Practices

Note
Location
bin/run.mjs:137
Finding

API Token Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:38-40, SKILL.md:46-48, bin/run.mjs:137-141
Vulnerability Type: Credential exposure through the process argument vector
Risk Level: Low

Vulnerable Code

bash
node {baseDir}/bin/run.mjs --operation "apiSolarCooperatorUserBloggerUserIdV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"userId":"<userId>"}'
js
if (flag === "--token") {
  parsed.token = value;
  index += 1;
  continue;
}

Technical Analysis

Although the token originates in the JUST_ONE_API_TOKEN environment variable, the documented command expands it into the --token command-line argument before Node starts. The plaintext credential therefore becomes part of the process argument vector.

Depending on the operating system, process-isolation configuration, container settings, audit policy, and monitoring software, command-line arguments may be visible through process inspection interfaces or retained by endpoint telemetry and audit systems. The documentation's instruction not to paste the token into chat messages, screenshots, or logs does not mitigate argument-vector exposure.

The implementation does not print the token itself, and the token is not hard-coded in the project. Exploitation requires local process visibility or access to telemetry that captures process arguments, which limits the severity.

Attack Path

  1. A user exports a valid token in JUST_ONE_API_TOKEN.
  2. The user runs the documented command.
  3. The shell expands $JUST_ONE_API_TOKEN and places its value after --token in the Node process arguments.
  4. A local observer, process-monitoring agent, audit facility, or telemetry collector captures the argument vector.
  5. The observer extracts the token and reuses it against JustOneAPI.
  6. Unauthorized API access continues within the token's privileges until expiration or revocation.

Impact Assessment

An attacker who obtai ...[truncated 541 chars]

Remediation
View remediation

Remediation Suggestions

  1. Read the credential directly from the declared environment variable rather than accepting it as a routine command-line argument:

    js
    const token = process.env.JUST_ONE_API_TOKEN;
    if (!token) {
      fail("JUST_ONE_API_TOKEN is required.");
    }
    
  2. Update the documented invocation to omit --token:

    bash
    JUST_ONE_API_TOKEN="..." node {baseDir}/bin/run.mjs \
      --operation "apiSolarCooperatorUserBloggerUserIdV1" \
      --params-json '{"userId":"<userId>"}'
    
  3. Prefer a secret manager or a permission-restricted credential source where the execution environment supports one.

  4. If environment variables are considered too exposed for the deployment model, accept the token through standard input or a permission-restricted file descriptor rather than through the argument vector.

  5. Avoid logging environment contents, command invocations, or authentication material.

  6. Deprecate --token; if backward compatibility requires temporary support, display a warning and prioritize the safer credential source.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill requires an authentication token as a query parameter and then appends all query parameters directly into the URL. Query-string secrets are commonly exposed through logs, browser history, proxy/CDN logs, monitoring systems, and error reporting, making token disclosure more likely than if the token were sent in an Authorization header. The skill context increases risk because this token is used to access creator profile data via a third-party API aggregator, so token leakage could enable unauthorized API use and data access under the user's account.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest-style JSON describes what the skill does but does not define any narrow activation conditions, trigger phrases, or exclusion conditions. In manifest files, missing specificity about when a skill should activate can make invocation behavior overly broad or ambiguous for downstream systems.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:41