Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Similar Creators API

Security checks for vulnerabilities and agentic risk

Overview

This is a focused API wrapper, but it passes a sensitive API token through command-line arguments and URL query parameters, which can expose the token in logs or process metadata.

Review before installing if the JustOneAPI token has meaningful account, billing, or quota privileges. Use a narrowly scoped token if available, avoid exposing command lines or logs, and rotate the token if it may have appeared in process telemetry or request logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:91
Finding

API Token Exposed Through Command-Line Arguments and URL Query Parameters

Content
View full analysis
"}' ``` The operation manifest defines the token as a required query parameter: ```js { "defaultValue": null, "description": "User authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" } ``` The executable injects the supplied credential into the request parameters: ```js const params = parseParams(args.paramsJson); applyDefaults(operation, params); injectToken(operation, params, args.token); validateRequired(operation, params); ``` All parameters whose location is `query`, including the token, are appended to the URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The generated specification confirms this behavior in `generated/operations.json:15-23` and `generated/operations.md:19`. ### Technical Analysis Passing the credential using `--token "$JUST_ONE_API_TOKEN"` expands the secret into the process argument vector. Depending on operating-system configuration and execution environment, command-line arguments may be visible through process inspection, shell or orchestration telemetry, diagnostic tooling, and execution wrappers. The token is then inserted into the HTTPS URL as a query parameter. TLS protects the request while it is transported across the network, but it ...[truncated 2028 chars]
Remediation
View remediation
"}' ``` Prefer supplying the environment variable through a secure secret manager rather than inline shell history. 5. If the upstream service only supports query-string authentication: - Document that constraint and its residual risk. - Use narrowly scoped, short-lived tokens. - Configure gateways, proxies, access logs, telemetry, and error reporting to redact the `token` query parameter. - Avoid logging request URLs or exception objects that may include the URL. - Rotate any token suspected of having appeared in process or URL logs. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and requires an API token, but it does not declare any explicit tool scope such as allowed tools or permissions. This creates a policy gap where an agent may execute outbound network actions without clear least-privilege constraints or reviewable authorization metadata, increasing the risk of unintended external requests or misuse of secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill accepts the authentication token as a query parameter and then appends all query parameters directly into the request URL. Tokens placed in URLs are commonly exposed through logs, browser or proxy histories, monitoring systems, referrer leakage, and error reporting, which can enable credential reuse or unauthorized API access if the token is captured. In this skill context, the risk is heightened because the token is a required credential for a third-party API and there is no warning to users that it will be sent this way.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest requires a token to be sent as a query parameter, and there is no user-facing warning or safer authentication handling indicated. Query parameters are more likely to be exposed in logs, browser histories, telemetry, and intermediary systems, increasing the risk of credential leakage if the token is sensitive.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This manifest-style JSON describes the skill's purpose in broad terms but does not define any explicit trigger phrases, activation boundaries, or exclusion conditions. Without narrow invocation guidance, a planner or dispatcher could match the skill on generic requests about similar creators or creator discovery more broadly than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file exposes that the skill requires a user authentication token, but it does not include any warning about the sensitivity of that credential, how it will be transmitted, or the privacy implications of using it. Under the markdown-specific missing-warning criterion, credential-related behavior should be disclosed when it could affect user privacy or account security.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:42