Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Creator Profile API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused JustOneAPI wrapper, but it handles the API token in a way that can expose it through process arguments and request URLs.

Review this before installing if the JustOneAPI token has billing, quota, or sensitive data access. Prefer running only in an environment where process command lines are not logged or visible to other users, use a narrowly scoped and revocable token if available, and rotate the token if you already used the documented command on a monitored system.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:132
Finding

API Token Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
"}' ``` ```markdown - Required: `JUST_ONE_API_TOKEN` - Pass the token with `--token "$JUST_ONE_API_TOKEN"`; do not paste token values into chat messages, screenshots, or logs. ``` `bin/run.mjs:75-79` constructs a URL and serializes all query parameters before issuing the network request: ```js const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); ``` `bin/run.mjs:132-152` accepts the token directly from the process argument vector: ```js function parseArgs(argv) { const parsed = { operation: null, paramsJson: "{}", token: null }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); } return parsed; } ``` `bin/run.mjs:174-186` copies the command-line secret into the request parameter collection: ```js function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { ...[truncated 3689 chars]
Remediation
View remediation
"}' ``` 2. **Prefer header-based authentication.** If supported by JustOneAPI, transmit the credential in an authorization header rather than the query string: ```js const requestInit = { headers: { accept: "application/json", authorization: `Bearer ${token}`, }, method: operation.method, }; ``` Ensure `token` is excluded from `applyQueryParams`. 3. **If query authentication is an unavoidable upstream requirement:** - Confirm that client, proxy, CDN, API gateway, server, tracing, and analytics configurations redact the `token` parameter. - Disable full-URL logging where possible. - Ensure redirects are disabled or carefully constrained so the credential cannot be forwarded to another origin. - Avoid including the constructed URL in exceptions, diagnostics, or debug output. - Use short-lived, narrowly scoped, and readily revocable tokens. - Document the residual logging risk for users. 4. **Prevent alternate token injection through `--params-json`.** Reject `token` in user-provided parameters and source it exclusively from the protected credential channel: ```js if (Object.prototype.hasOwnProperty.call(params, "token")) { fail("The token must not be supplied through --params-json."); } ``` 5. **Rotate potentially exposed credentials.** Users who have executed the documented command should review process telemetry and shell-audit systems and rotate the token if command lines may have been retained. ]] ...[truncated 1 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to make an external API call and explicitly depends on a network-capable runtime, but it does not declare any explicit tool scope such as allowed-tools or permissions. That omission weakens policy enforcement and reviewability because consumers cannot easily tell that network access is required or constrain it up front, increasing the chance of unintended outbound requests or overbroad execution in agent environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs an HTTP request after placing the required token parameter into the query string, which sends authentication data to an external API. There is no confirmation prompt, user-facing log/print warning, or inline warning comment/docstring disclosing that sensitive credential material will be transmitted.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:42