Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Follower Distribution API

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it handles the JustOneAPI token in ways that can expose it through process arguments and URL query logs.

Install only if you are comfortable sending your JustOneAPI token and kolId to api.justoneapi.com. Prefer a narrowly scoped token, rotate it if it may have appeared in process or URL logs, and avoid using this on shared systems where command-line arguments are monitored.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:228
Finding

Authentication Token Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
"}' ``` `SKILL.md:48` ```markdown - Pass the token with `--token "$JUST_ONE_API_TOKEN"`; do not paste token values into chat messages, screenshots, or logs. ``` `bin/run.mjs:29-35` ```js { "defaultValue": null, "description": "User authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" } ``` `bin/run.mjs:84-90` ```js const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, }; ``` `bin/run.mjs:172-183` ```js function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` `bin/run.mjs:228-238` ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` ### Technical Analysis The documented invocation expands `JUST_ONE_API_TOKEN` into the Node.js command line as the value of `--token`. Depending on the ...[truncated 2565 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes a networked API via a Node helper but does not declare any explicit tool scope such as allowed network access or permissions. This creates a transparency and policy-enforcement gap: a host may expose network-capable execution without users or orchestrators being able to constrain or review that capability, increasing the risk of unintended outbound requests or misuse if the skill is modified or composed with other inputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly models the authentication token as a query parameter and later appends all query parameters to the URL, which causes the credential to be placed in the request line. Query-string tokens are commonly exposed through logs, browser/history tooling, proxies, monitoring systems, and error telemetry, making credential leakage more likely even when HTTPS is used. In this API-wrapper context, the risk is increased because the code provides no warning or alternative secure transport mechanism.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script constructs a remote URL and performs a fetch request to api.justoneapi.com using user-supplied parameters including token and kolId. While the network call is central to the skill's purpose, the code itself provides no explicit user-facing notice, log, or comment that these values will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest-style JSON describes the skill's purpose and operation but provides no explicit activation phrases, scope limits, or negative examples clarifying when the skill should or should not be invoked. In systems that infer invocation from descriptions, broad API-purpose text like this can lead to unintended matching for general Xiaohongshu analytics requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The natural-language metadata is entirely specialized to the Xiaohongshu Creator Marketplace context, but it does not state whether this locale/platform specificity is intentional, user-selected, or region-limited. Because policy flags can arise when a skill imposes a specific language or locale context without opt-in, this should be documented more clearly.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:42