Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Creator Content Tags API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrowly scoped API wrapper, but it handles the JustOneAPI token in a way that can expose it through command arguments and URL query strings.

Review before installing if your JustOneAPI token has broad access, paid quota, or sensitive account permissions. Prefer short-lived, narrowly scoped tokens if available, avoid shared machines or verbose command logging, and rotate the token if it may have appeared in process telemetry or URL logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:18
Finding

Authentication token exposed through command-line arguments and URL query parameters

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:18-26, bin/run.mjs:67-89, bin/run.mjs:139-148, bin/run.mjs:176-187, and bin/run.mjs:219-241; related usage guidance appears at SKILL.md:41-49
Vulnerability Type: Authentication credential exposure
Risk Level: Medium

The Skill requires an API token and legitimately sends it to the fixed HTTPS host api.justoneapi.com. However, the token is accepted as a command-line argument and then transmitted as a URL query parameter.

Relevant parameter declaration:

js
      {
        "defaultValue": null,
        "description": "User authentication token.",
        "enumValues": [],
        "location": "query",
        "name": "token",
        "required": true,
        "schemaType": "string"
      },

Relevant request construction and transmission:

js
const params = parseParams(args.paramsJson);
applyDefaults(operation, params);
injectToken(operation, params, args.token);
validateRequired(operation, params);

const baseUrl = manifest.baseUrl;
const url = new URL(operation.path, ensureBaseUrl(baseUrl));
applyPathParams(operation, params, url);
applyQueryParams(operation, params, url);

const requestInit = {
  headers: {
    "accept": "application/json",
  },
  method: operation.method,
};

if (operation.requestBody && params.body !== undefined) {
  requestInit.body = JSON.stringify(params.body);
  requestInit.headers["content-type"] = operation.requestBody.contentType || "application/json";
}

let response;
try {
  response = await fetch(url, requestInit);

Relevant command-line parsing and token injection:

js
    if (flag === "--token") {
      parsed.token = value;
      index += 1;
      continue;
    }
js
function injectToken(operation, params, cliToken) {
  const tokenParam = operation.parameters.find((parameter) => parameter.name === "token");
  if (!token
...[truncated 3934 chars]
Remediation
View remediation

Remediation Suggestions

  1. Use an authorization header: Change the API contract and client implementation to send the credential in an HTTP header, preferably:

    js
    const requestInit = {
      method: operation.method,
      headers: {
        "accept": "application/json",
        "authorization": `Bearer ${token}`,
      },
    };
    

    Do not add the token to URL.searchParams.

  2. Read the token directly from the environment: Replace the documented --token argument with process.env.JUST_ONE_API_TOKEN so the secret is not placed in the command-line argument vector.

    js
    const token = process.env.JUST_ONE_API_TOKEN;
    if (!token) {
      fail("JUST_ONE_API_TOKEN is required.");
    }
    
  3. Reject token values in general parameters: Prevent callers from supplying token through --params-json, ensuring that credentials use only the dedicated secure authentication path.

  4. Apply log redaction: Configure client diagnostics, API gateways, proxies, application servers, tracing platforms, and monitoring systems to redact token query parameters and authorization headers.

  5. If query authentication cannot be changed: Clearly document the residual exposure, avoid printing or logging the constructed URL, use short-lived and narrowly scoped tokens, restrict access to infrastructure logs, and establish token rotation and revocation procedures.

  6. Rotate potentially exposed credentials: Revoke and replace tokens that may already have appeared in process telemetry or URL logs.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a network-capable helper (node {baseDir}/bin/run.mjs calling a remote API) but does not declare any explicit tool scope such as allowed network access or permissions. This creates a governance gap: an agent/runtime may permit broader-than-intended outbound access or make unsafe assumptions about what the skill is authorized to do, reducing reviewability and increasing the chance of misuse or data exfiltration through network calls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill defines the authentication token as a query parameter and later appends all query parameters directly into the URL. Query-string tokens are commonly exposed through logs, browser history, proxy telemetry, referrer leakage, and monitoring systems, making credential disclosure more likely than if the token were sent in an Authorization header.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The operation requires an authentication token to be sent in the URL query string, which is commonly exposed through server logs, browser history, intermediary proxies, analytics tooling, and referrer leakage. Even though the endpoint uses HTTPS, placing credentials in the URL unnecessarily increases the chance of credential disclosure and unauthorized API access if logs or traces are exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends a request to an external API using sensitive inputs including a user authentication token and a user ID. While network access is the skill's purpose, the file itself contains no visible warning, confirmation, or user-facing disclosure about transmitting those values to a third-party endpoint.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:41