T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:24- Finding
Authentication Token Transmitted in the URL Query String
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a narrowly scoped API helper for one JustOneAPI follower-analytics endpoint, with a credential-handling risk users should understand.
Install only if you are comfortable giving this skill a JustOneAPI token for the listed Xiaohongshu follower-distribution endpoint. Prefer a short-lived or limited-scope token, avoid shared machines or process logging, and rotate the token if it may have been captured in command-line or URL logs.
bin/run.mjs:24Authentication Token Transmitted in the URL Query String
SKILL.md:40Authentication Token Exposed Through Process Command-Line Arguments
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill sends the authentication token as a URL query parameter by appending all query parameters, including token, into url.searchParams. Query-string tokens are commonly exposed through logs, browser or proxy history, monitoring systems, referrer leakage, and error messages, making credential disclosure more likely even when HTTPS is used. In this skill context, the token is a required auth secret for a third-party API, so placing it in the URL is unnecessarily risky and directly increases the chance of credential compromise.
Passing an authentication token in a query parameter is dangerous because query strings are commonly logged by servers, proxies, monitoring tools, browser history, and intermediary infrastructure. This increases the chance of credential exposure and replay, especially for an API handling follower analytics data that may be sensitive or access-controlled.
This manifest-style JSON describes a skill that calls a follower distribution endpoint, but it does not specify any explicit invocation constraints, trigger phrases, or exclusion conditions. For manifest files, the absence of clear trigger scope can make activation ambiguous, especially for a broadly described analytics function.
Detected: suspicious.secret_argv_exposure