Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Follower Summary API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a focused API wrapper, but it handles the user’s API token in ways that can expose it through command-line arguments and request URLs.

Review this before installing if the JustOneAPI token has broad or long-lived access. Use a narrowly scoped token if available, avoid logging commands or full request URLs, and rotate the token if it may have appeared in shell history, process telemetry, or API gateway logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

API Token Exposed Through Command-Line Arguments

Content
View full analysis
"}' ``` ```js if (flag === "--token") { parsed.token = value; index += 1; continue; } ``` ### Technical Analysis The documented invocation passes the JustOneAPI authentication token through the `--token` command-line argument. The helper explicitly parses and retains this argument. Command-line arguments may be visible to other local users or monitoring systems through process inspection, shell auditing, command histories, crash diagnostics, process telemetry, and automation logs. Expanding an environment variable into an argument does not preserve its confidentiality after process creation. This behavior exceeds the minimum privilege necessary for reading the configured `JUST_ONE_API_TOKEN` environment variable. The Skill metadata already declares that environment variable as required, so the helper could read it directly without placing the secret in the process argument vector. ### Attack Path 1. A user follows the command documented in `SKILL.md`. 2. The shell expands `$JUST_ONE_API_TOKEN` into the Node process argument list. 3. While the helper is running, a local observer or process-monitoring service records the command line. 4. The observer extracts the value following `--token`. 5. The exposed token is reused against JustOneAPI within the permissions and lifetime assigned to that credential. ### Impact Assessment Successful exploitation discloses the JustOneAPI authentication token. An attacker could consume the associated API quota and invoke API operations authorized for that token. The exact accessible data and operations depend on server-side token scope; the audited code does not establis ...[truncated 260 chars]
Remediation
View remediation
"}' ``` 3. Ensure deployment wrappers, debug output, process telemetry, and error handlers never record the token. 4. Rotate any token that may already have appeared in process-monitoring, shell-audit, or automation logs. 5. Where supported, use short-lived, narrowly scoped credentials to reduce the impact of accidental disclosure. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:19
Finding

Authentication Token Transmitted in the Request URL Query String

Content
View full analysis
item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` Consequently, the resulting request has the effective form: ```text https://api.justoneapi.com/api/xiaohongshu-pgy/api/solar/kol/dataV3/fansSummary/v1?token=&userId= ``` ### Technical Analysis The helper sends the authentication token in the URL query string. Although the request uses HTTPS and is sent to the fixed, declared host `api.justoneapi.com`, HTTPS only protects the request while it is in transit. It does not prevent the complete URL from being retained by endpoint-side infras ...[truncated 1845 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and requires an API token, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch can cause the runtime or a reviewing agent to underestimate the skill's ability to make outbound requests, increasing the risk of unintended external data access or token-backed API calls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill sends the authentication token as a URL query parameter, which is commonly exposed in logs, browser history, proxy records, monitoring systems, and error messages. Even though the base URL uses HTTPS, query-string secrets are still more likely to be retained or disclosed by surrounding infrastructure, increasing the chance of credential leakage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Passing an authentication token in a query parameter is dangerous because query strings are commonly logged by servers, proxies, observability tools, browser history, and intermediaries. In this skill context, the token grants access to creator-marketplace follower analytics, so leakage could enable unauthorized API access and exposure of potentially sensitive account data.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This manifest describes what the skill does but does not define any specific trigger phrases, context limits, or exclusion conditions. For manifest files, missing specificity on when the skill should activate can lead to overly broad or unintended invocation behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:41