Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Follower Summary API

Security checks for vulnerabilities and agentic risk

Overview

This is a focused API-wrapper skill that calls one disclosed JustOneAPI endpoint, with a real but disclosed credential-handling risk around token placement.

Install only if you trust JustOneAPI and are comfortable sending your kolId and API token to api.justoneapi.com. Use a narrowly scoped token where possible, avoid logging full commands or URLs, and rotate the token if you suspect command history, process telemetry, or request logs exposed it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:152
Finding

API Token Exposure Through Command-Line Arguments

Content
View full analysis
"}' ``` ```js function parseArgs(argv) { const parsed = { operation: null, paramsJson: "{}", token: null }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); } return parsed; } ``` ### Technical Analysis The documented invocation expands `JUST_ONE_API_TOKEN` into the process argument vector, and the runner explicitly parses it from `process.argv`. Secrets passed this way may be observable through process-inspection interfaces, privileged monitoring tools, shell tracing, command telemetry, crash diagnostics, or orchestration metadata. Although access to process arguments depends on operating-system controls and local privileges, command-line arguments are not an appropriate secret-transport mechanism when the token is already available as an environment variable. This exposure is not required for the Skill’s declared API-wrapper functionality. ### Attack Path 1. A user follows the documented command and starts the runner with a valid token supplied through `--token`. 2. While the process is running, a local actor or monitoring component with permission to inspect process metadata records the argument vector. 3. The actor extracts the token following the `--token` argument. 4. The token is replayed a ...[truncated 558 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:228
Finding

API Token Transmitted in the URL Query String

Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` ### Technical Analysis Because `token` is marked with `location: "query"`, `applyQueryParams` serializes the secret into the URL as a query parameter. HTTPS protects the URL while it travels between the client and the TLS endpoint, but it does not prevent the complete URL from being retained by the destination se ...[truncated 1509 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) to call an external API, but the manifest does not declare an explicit tool scope such as permissions or allowed-tools. This weakens policy enforcement and reviewability because an agent may be able to perform outbound requests without the skill clearly advertising that capability, increasing the risk of unintended data egress or misuse of the provided API token.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill defines the authentication token as a query parameter and injects it into the request URL, causing the secret to be placed in the URL rather than a header or body. Query-string tokens are commonly exposed through logs, browser/history equivalents, proxy infrastructure, monitoring systems, and error messages, increasing the chance of credential leakage even when HTTPS is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly requires a user authentication token in a query parameter but provides no warning about secure handling, storage, logging, or exposure risks. Query-string tokens are especially sensitive because they are commonly recorded in browser history, proxy logs, analytics systems, and server access logs, increasing the chance of credential leakage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language description, display name, tags, and skill name all lock the skill to the Xiaohongshu Creator Marketplace context, which implies a specific locale/platform specialization. Because the file does not clearly document that this regional/platform constraint is intentional or user-selected, it may violate the policy against forcing a specific language/locale without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:42