Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Cost Effectiveness Analysis API

Security checks for vulnerabilities and agentic risk

Overview

The skill is narrowly scoped to one JustOneAPI lookup, but it handles the user's API token in a way that could leak through command or URL logs.

Install only if you are comfortable using a JustOneAPI token for this endpoint. Prefer short-lived or restricted tokens if available, avoid running it in environments that log process arguments or full URLs, and rotate the token if you suspect command or request logs captured it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:226
Finding

API Credential Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
"}' ``` The executable parses the token from the command line: ```js function parseArgs(argv) { const parsed = { operation: null, paramsJson: "{}", token: null }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); } return parsed; } ``` It then injects the credential into the request parameters: ```js function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` The token is defined as a query parameter and appended to the request URL: ```js { "defaultValue": null, "description": "User authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" } ``` ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) ...[truncated 3593 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill sends the authentication token as a URL query parameter, which is commonly exposed through logs, browser/history records, proxy infrastructure, monitoring systems, and error telemetry. Even though the request uses HTTPS, placing credentials in the URL increases the chance of accidental credential disclosure well beyond the immediate transport channel.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This JSON manifest describes the skill's purpose and identity but provides no explicit trigger phrases, activation boundaries, or negative examples. For manifest files, the absence of specificity about when the skill should or should not be invoked can lead to overly broad matching by an agent runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The skill is entirely framed around Xiaohongshu Creator Marketplace (Pugongying), a specific Chinese platform/context, and does not indicate whether this locale/domain restriction is optional, user-selected, or justified as region-specific. Under the policy, locale or language constraints should be opt-in or clearly documented when they are inherent to the tool.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:42