Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Follower Growth History API

Security checks for vulnerabilities and agentic risk

Overview

The skill is narrowly aimed at one JustOneAPI endpoint, but it handles the user's API token in a way that can expose it through command-line arguments and URL query logs.

Review this skill before installing if the JustOneAPI token has meaningful account access, billing impact, or quota value. Use a narrowly scoped token if possible, avoid sharing command transcripts or logs, and rotate the token if it may have been exposed through process monitoring or URL logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:254
Finding

API Credential Exposed Through URL Query String and Command-Line Argument

Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` ```js // bin/run.mjs:254-262 function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` ```markdown
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a network-capable helper (node {baseDir}/bin/run.mjs) and is explicitly designed to call an external API, but it does not declare any tool scope such as permissions or allowed-tools. That mismatch weakens policy enforcement and reviewability, because the runtime may permit broader outbound actions than the skill metadata communicates, increasing the chance of unintended or abused network access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code injects the user authentication token into the token query parameter and sends it in the request URL. Query-string secrets are commonly exposed through logs, browser/history equivalents, monitoring systems, proxies, and upstream infrastructure, so placing an auth token there unnecessarily increases credential leakage risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The API requires a sensitive authentication token to be supplied in the URL query string, which is commonly logged by clients, proxies, gateways, browser history, and observability systems. Even though the base URL uses HTTPS, query parameters are still widely exposed in logs and telemetry, increasing the chance of credential leakage and unauthorized API access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a markdown file, so SQP-2 applies to missing user warnings in documentation. The parameter description identifies a sensitive authentication token, but the file gives no warning about secure handling, exposure risks in query strings, or privacy impact when submitting authenticated requests.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:46