Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) User Published Notes API

Security checks for vulnerabilities and agentic risk

Overview

This is a focused JustOneAPI wrapper, but it sends the required API token in the request URL query string, which is risky enough for review before installation.

Install only if you are comfortable sending userId values and your JustOneAPI token to api.justoneapi.com. Prefer a narrowly scoped, revocable token, avoid sharing transcripts or logs containing command lines or request URLs, and rotate the token if a URL containing it is exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:22
Finding

API Token Transmitted in URL Query String

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:22-30, 137-139, 260-268
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

js
{
  "defaultValue": null,
  "description": "User authentication token.",
  "enumValues": [],
  "location": "query",
  "name": "token",
  "required": true,
  "schemaType": "string"
}
js
injectToken(operation, params, args.token);
validateRequired(operation, params);
// ...
applyQueryParams(operation, params, url);
js
function applyQueryParams(operation, params, url) {
  for (const parameter of operation.parameters.filter((item) => item.location === "query")) {
    const value = params[parameter.name];
    if (value === undefined) {
      continue;
    }
    appendValue(url.searchParams, parameter.name, value);
  }
}

Technical Analysis

The operation manifest defines the authentication token as a query parameter. The helper injects the caller-supplied token into the parameter object and then serializes every query parameter into the request URL. Consequently, requests take the following form:

text
https://api.justoneapi.com/api/xiaohongshu-pgy/api/solar/kol/dataV2/notesDetail/v1?token=SECRET&userId=...

HTTPS protects the URL while it is in transit, but it does not prevent the complete URL from being recorded at endpoints or within trusted infrastructure. Query strings may appear in API gateway logs, reverse-proxy access logs, server logs, tracing systems, monitoring products, diagnostic output, or error reports. Authentication secrets are therefore more likely to be retained and exposed than credentials carried in an authorization header.

Sending authentication data to the documented JustOneAPI service is necessary for the Skill's functionality. However, placing the credential in the URL exceeds secure minimum-disclosure practices when header-base ...[truncated 1486 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace query-string authentication with an HTTP authorization header whenever supported by the upstream API:

    js
    const requestInit = {
      headers: {
        accept: "application/json",
        authorization: `Bearer ${args.token}`,
      },
      method: operation.method,
    };
    
  2. Remove token from the operation's query-parameter manifest and ensure it is never passed to URLSearchParams.

  3. Update generated/operations.json, generated/operations.md, and SKILL.md so the documented authentication mechanism matches the secure implementation.

  4. If JustOneAPI requires query-string authentication and cannot support headers:

    • Use narrowly scoped and short-lived tokens.
    • Redact the token parameter in gateways, proxies, tracing systems, error reports, and access logs.
    • Disable query-string collection where operationally possible.
    • Restrict access to logs and telemetry using least privilege.
    • Establish short retention periods and secure deletion policies.
    • Rotate the token immediately if a URL containing it is disclosed.
  5. Prefer reading the token directly from JUST_ONE_API_TOKEN rather than requiring it on the command line, because command-line arguments may also be visible to local process-inspection tools or retained in shell history.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill performs external network access to a third-party API but does not declare an explicit tool scope such as allowed-tools or permissions. That weakens transparency and policy enforcement, making it easier for an agent runtime or user to miss that the skill can transmit data off-platform, including identifiers and query parameters.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill defines the authentication token as a query parameter and later appends all query parameters directly into the request URL. Query-string tokens are commonly exposed through logs, browser/history layers, proxies, monitoring systems, crash reports, and server access logs, increasing the chance of credential leakage even when HTTPS is used. In this skill context, the risk is real because the code is an API wrapper for authenticated access and gives no warning that the secret will be transmitted in the URL.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The operation documentation requires a token query parameter for authentication but provides no warning that this value is a sensitive credential. Putting auth tokens in query strings increases the chance they will be exposed through logs, browser history, analytics, referrers, and copied URLs, especially in agent or API-invocation workflows that may persist request metadata. In this skill context, the risk is somewhat elevated because the skill is specifically designed to have users supply a credential to a third-party proxy API (JustOneAPI) without any guidance on secure handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill sends a userId to an external API service but does not warn users in the description that this identifier will be transmitted to a third party. Even if userId is not highly sensitive in all contexts, omission of this disclosure can lead to unintended data sharing and weak informed consent around external processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The operation description and display name are hard-coded to Xiaohongshu Creator Marketplace, a China-specific platform context, with no indication that users can choose language or locale or that the regional constraint is explicitly justified. Under the policy rule for natural-language locale constraints, this should be documented as opt-in or region-specific if intentional.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:50