Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Creator Core Metrics API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent JustOneAPI wrapper, but it handles an API token in ways that can expose it through command-line arguments and URL query strings.

Review before installing if you use a real JustOneAPI token. Prefer short-lived, low-scope tokens if available, avoid placing tokens in chat, screenshots, shell history, or logs, and rotate any token that may have been exposed through command history or request logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:129
Finding

API Token Exposure Through Process Arguments and URL Query Parameters

Content
View full analysis
Remediation
View remediation
`, or the service's documented private authentication header. - Remove the token from `operation.parameters` and ensure it cannot be processed by `applyQueryParams()`. 3. **If the upstream service strictly requires query authentication:** - Retain HTTPS and keep the destination host fixed. - Read the token directly from the environment rather than accepting it through the CLI. - Ensure proxies, gateways, servers, and observability tools redact the `token` query parameter. - Never include the constructed URL, query string, or token in errors, traces, analytics, or debug logs. - Request support for header-based credentials from the API provider. 4. **Harden token handling.** - Validate that the token is non-empty without printing it. - Keep tokens short-lived and narrowly scoped where the provider supports those controls. - Rotate any token that may already have appeared in process or request logs. - Restrict access to execution telemetry and API infrastructure logs. 5. **Update the documentation.** - Replace the documented `--token "$JUST_ONE_API_TOKEN"` invocation with automatic environment loading. - Explicitly warn users not to place tokens in `--params-json`, chat messages, screenshots, shell history, or logs. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and requires an API token, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization gap where an agent platform may permit broader-than-intended network behavior or fail to present clear consent boundaries to users before external API access occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends the user authentication token as a URL query parameter via applyQueryParams, which exposes the secret more broadly than necessary. Query-string tokens can be captured in logs, proxy records, browser/history artifacts, monitoring systems, and error telemetry, increasing the chance of credential leakage even though the request uses HTTPS.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The API requires a sensitive authentication token to be sent as a query parameter, which is unsafe because query strings are commonly logged by clients, proxies, gateways, browser history, and observability systems. In this skill context, the token is also sent to an external third-party API service, and the manifest provides no warning or safer transport mechanism, increasing the risk of credential exposure and downstream account misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This JSON manifest describes what the skill does, but it provides no specific invocation phrase, scope limitation, or negative examples for when the skill should or should not be used. In manifest files, that lack of trigger specificity can cause unintended activation because the description is broad enough to match general requests about creator metrics.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents a required token query parameter for an API call, which is a credential-like value, but it provides no warning about protecting the token or avoiding accidental exposure in logs, URLs, or shared examples. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors affecting privacy or security.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:50