Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Follower Distribution API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrowly scoped API helper for one JustOneAPI follower-analytics endpoint, with a credential-handling risk users should understand.

Install only if you are comfortable giving this skill a JustOneAPI token for the listed Xiaohongshu follower-distribution endpoint. Prefer a short-lived or limited-scope token, avoid shared machines or process logging, and rotate the token if it may have been captured in command-line or URL logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:24
Finding

Authentication Token Transmitted in the URL Query String

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:40
Finding

Authentication Token Exposed Through Process Command-Line Arguments

Content
View full analysis
"}' ``` ```md - Pass the token with `--token "$JUST_ONE_API_TOKEN"`; do not paste token values into chat messages, screenshots, or logs. ``` ```js if (flag === "--token") { parsed.token = value; index += 1; continue; } ``` ### Technical Analysis The documented invocation expands `JUST_ONE_API_TOKEN` in the shell and passes the resulting secret as the value of `--token`. This places the credential in the Node process's argument vector. Depending on the host operating system and its security configuration, process arguments may be visible to other authorized local users, process-monitoring agents, container administrators, crash collectors, audit systems, or execution telemetry. The documentation warns against logging the token but prescribes an invocation method that can expose it to process-level observation. The Skill already declares `JUST_ONE_API_TOKEN` as its required environment variable, so converting that environment variable into a command-line argument is unnecessary for its declared functionality. ### Attack Path 1. A user follows the documented command and supplies the token using `--token "$JUST_ONE_API_TOKEN"`. 2. The shell expands the variable before starting Node. 3. The plaintext token appears in the process argument vector. 4. A local process observer or telemetry service with sufficient operating-system permissions records or reads the arguments while the process is running. 5. The observer extracts and reuses the token against JustOneAPI. This path requires local process-inspection privileges or access to telemetry that captures command lines. It does not create tho ...[truncated 402 chars]
Remediation
View remediation
"}' ``` 4. Ensure execution telemetry, process monitoring, and crash reporting redact credential-bearing arguments during the migration period. 5. Avoid printing the environment variable or including it in thrown errors, debug output, or backend error payloads. 6. Prefer short-lived and narrowly scoped API tokens so that any accidentally observed credential has limited utility. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill sends the authentication token as a URL query parameter by appending all query parameters, including token, into url.searchParams. Query-string tokens are commonly exposed through logs, browser or proxy history, monitoring systems, referrer leakage, and error messages, making credential disclosure more likely even when HTTPS is used. In this skill context, the token is a required auth secret for a third-party API, so placing it in the URL is unnecessarily risky and directly increases the chance of credential compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Passing an authentication token in a query parameter is dangerous because query strings are commonly logged by servers, proxies, monitoring tools, browser history, and intermediary infrastructure. This increases the chance of credential exposure and replay, especially for an API handling follower analytics data that may be sensitive or access-controlled.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This manifest-style JSON describes a skill that calls a follower distribution endpoint, but it does not specify any explicit invocation constraints, trigger phrases, or exclusion conditions. For manifest files, the absence of clear trigger scope can make activation ambiguous, especially for a broadly described analytics function.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:41