T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:22- Finding
API Token Transmitted in URL Query String
- Content
View full analysis
Vulnerability Details
File Location:
bin/run.mjs:22-30, 137-139, 260-268
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: MediumVulnerable Code
js { "defaultValue": null, "description": "User authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" }js injectToken(operation, params, args.token); validateRequired(operation, params); // ... applyQueryParams(operation, params, url);js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } }Technical Analysis
The operation manifest defines the authentication token as a query parameter. The helper injects the caller-supplied token into the parameter object and then serializes every query parameter into the request URL. Consequently, requests take the following form:
text https://api.justoneapi.com/api/xiaohongshu-pgy/api/solar/kol/dataV2/notesDetail/v1?token=SECRET&userId=...HTTPS protects the URL while it is in transit, but it does not prevent the complete URL from being recorded at endpoints or within trusted infrastructure. Query strings may appear in API gateway logs, reverse-proxy access logs, server logs, tracing systems, monitoring products, diagnostic output, or error reports. Authentication secrets are therefore more likely to be retained and exposed than credentials carried in an authorization header.
Sending authentication data to the documented JustOneAPI service is necessary for the Skill's functionality. However, placing the credential in the URL exceeds secure minimum-disclosure practices when header-base ...[truncated 1486 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace query-string authentication with an HTTP authorization header whenever supported by the upstream API:
js const requestInit = { headers: { accept: "application/json", authorization: `Bearer ${args.token}`, }, method: operation.method, }; -
Remove
tokenfrom the operation's query-parameter manifest and ensure it is never passed toURLSearchParams. -
Update
generated/operations.json,generated/operations.md, andSKILL.mdso the documented authentication mechanism matches the secure implementation. -
If JustOneAPI requires query-string authentication and cannot support headers:
- Use narrowly scoped and short-lived tokens.
- Redact the
tokenparameter in gateways, proxies, tracing systems, error reports, and access logs. - Disable query-string collection where operationally possible.
- Restrict access to logs and telemetry using least privilege.
- Establish short retention periods and secure deletion policies.
- Rotate the token immediately if a URL containing it is disclosed.
-
Prefer reading the token directly from
JUST_ONE_API_TOKENrather than requiring it on the command line, because command-line arguments may also be visible to local process-inspection tools or retained in shell history.
-
