Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Cost Effectiveness Analysis API

Security checks for vulnerabilities and agentic risk

Overview

The skill is narrowly focused on one JustOneAPI lookup, but it handles the required API token in a way that can expose credentials through process arguments and URL logs.

Review this before installing if you are uncomfortable with API tokens appearing in command-line arguments or request URLs. Use a narrowly scoped, revocable JustOneAPI token if possible, avoid logging full commands or URLs, and rotate the token if you suspect it was captured.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:17
Finding

API Credential Exposure Through Query-String Authentication and Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:17-26, bin/run.mjs:67-82, bin/run.mjs:172-184, bin/run.mjs:224-238, and SKILL.md:41-49
Vulnerability Type: API credential exposure
Risk Level: Medium

Vulnerable Code

The operation metadata defines the authentication token as a query parameter:

js
{
  "defaultValue": null,
  "description": "User authentication token.",
  "enumValues": [],
  "location": "query",
  "name": "token",
  "required": true,
  "schemaType": "string"
}

The token is injected into the parameter collection and subsequently appended to the request URL:

js
const params = parseParams(args.paramsJson);
applyDefaults(operation, params);
injectToken(operation, params, args.token);
validateRequired(operation, params);

const baseUrl = manifest.baseUrl;
const url = new URL(operation.path, ensureBaseUrl(baseUrl));
applyPathParams(operation, params, url);
applyQueryParams(operation, params, url);

const requestInit = {
  headers: {
    "accept": "application/json",
  },
  method: operation.method,
};

let response;
try {
  response = await fetch(url, requestInit);
js
function injectToken(operation, params, cliToken) {
  const tokenParam = operation.parameters.find((parameter) => parameter.name === "token");
  if (!tokenParam || params.token !== undefined) {
    return;
  }
  if (!cliToken) {
    fail("--token is required for this operation.", {
      operationId: operation.operationId,
    });
  }
  params.token = cliToken;
}
js
function applyQueryParams(operation, params, url) {
  for (const parameter of operation.parameters.filter((item) => item.location === "query")) {
    const value = params[parameter.name];
    if (value === undefined) {
      continue;
    }
    appendValue(url.searchParams, parameter.name, value);
  }
}

function appendValue(searchParams, name, value)
...[truncated 3833 chars]
Remediation
View remediation

Remediation Suggestions

  1. Move authentication out of the URL. If supported by JustOneAPI, transmit the credential in an authorization header:

    js
    const token = args.token || process.env.JUST_ONE_API_TOKEN;
    if (!token) {
      fail("JUST_ONE_API_TOKEN is required.");
    }
    
    const requestInit = {
      method: operation.method,
      headers: {
        accept: "application/json",
        authorization: `Bearer ${token}`,
      },
    };
    
  2. Read the token directly from the environment. Prefer process.env.JUST_ONE_API_TOKEN and remove the documented --token argument to reduce exposure through process listings and execution telemetry.

  3. Prevent credentials from entering generic parameter handling. Remove token from operation.parameters and do not store it in the same object as ordinary query parameters.

  4. Implement explicit redaction. Ensure request logging, errors, traces, and telemetry replace token values with a fixed marker. Never print fully constructed URLs containing authentication material.

  5. If query authentication is mandated by the remote API, document the residual risk, request header-based authentication support from the provider, disable query-string logging where possible, tightly restrict access to proxy and server logs, shorten log retention, and use narrowly scoped, short-lived tokens.

  6. Rotate potentially exposed credentials. Revoke and replace tokens that may already have appeared in process metadata or URL logs. Monitor account activity for unauthorized requests and quota anomalies.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes a Node helper that performs outbound API requests, but the manifest does not declare any explicit tool scope such as allowed network permissions or destination restrictions. This creates a trust and policy gap: a runner may grant broader network capability than users expect, enabling unreviewed external communication and increasing the blast radius if the helper is modified or abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill requires an authentication token as a query parameter and automatically injects it into the request URL. Query-string credentials are commonly exposed through logs, browser/history tooling, proxy infrastructure, monitoring systems, and error reporting, making accidental credential disclosure more likely even when HTTPS is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Passing an authentication token in the query string is risky because query parameters are commonly logged by servers, proxies, client tooling, browser history, and observability systems. Even over HTTPS, the token can be exposed through operational logs or accidental sharing, enabling unauthorized API access if leaked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The manifest strings hard-code a Xiaohongshu-specific Chinese platform context and naming, but the file does not indicate that this locale/domain restriction is optional, user-selectable, or justified as a region-specific compliance requirement. Under the policy, locale-specific constraints should be explicitly offered as a choice or clearly documented as intentionally region-bound.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest-level description frames the skill as a simple cost-effectiveness lookup using only a userId. However, the operation definition requires both userId and a token, which materially expands the inputs and behavior needed to use the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This manifest-style JSON describes what the skill does but provides no explicit activation phrases, limiting context, or exclusion conditions. Without any trigger specificity, the invocation scope is ambiguous and could allow broader-than-intended activation in systems that infer usage from descriptions.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:41