Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Creator Feature Tags API

Security checks for vulnerabilities and agentic risk

Overview

This focused API wrapper appears legitimate, but it handles the API token through command-line arguments and URL query parameters, which can expose credentials in logs or process metadata.

Review before installing if the JustOneAPI token has broad privileges, billing impact, or long lifetime. Use a narrowly scoped, revocable token where possible, avoid running it in environments that log process arguments or full URLs, and query only creator IDs you are authorized to access.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:31
Finding

API Token Exposed Through Command-Line Arguments and URL Query Parameters

Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` All parameters designated as query parameters—including the token—are appended to the request URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The resulting URL is transmitted to the fixed JustOneAPI endpoint: ```js const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, }; let response; try { response = await fetch(url, requestInit); } ``` The documented invocation also supplies the secret through a command-line argument: ```bash node {baseDir}/bin/run.mjs --operation "ap ...[truncated 2641 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a network-capable helper (node {baseDir}/bin/run.mjs) and transmits a secret token, but it does not explicitly declare tool permissions or allowed network scope. In an agent environment, missing scope declarations can cause overbroad execution privileges, making it harder to enforce least privilege or constrain unexpected outbound requests from the helper.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is broad and does not constrain when the skill should be invoked or what authorization checks should precede use. In an agent setting, vague trigger scope can cause overbroad or accidental invocation against arbitrary user IDs, increasing the chance of unnecessary access to creator profiling data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The operation requires a sensitive authentication token in a query parameter, but the manifest provides no user-facing warning or handling guidance. Query-string tokens are more likely to be exposed through logs, monitoring systems, browser history, or intermediary infrastructure, which can lead to credential leakage and unauthorized API access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents a required token query parameter and labels it as a user authentication token, which is sensitive credential material. The description provides no warning about secure handling, exposure in logs/URLs, or privacy implications, even though markdown files should disclose behaviors that could affect user data or privacy.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:41