Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Creator Note List API

Security checks for vulnerabilities and agentic risk

Overview

This is a narrow JustOneAPI wrapper, but it handles the required API token in a URL query string, which creates a real credential-exposure risk.

Review before installing if the JustOneAPI token has broad, paid, or long-lived authority. Use a narrowly scoped token if possible, avoid logging command lines or full request URLs, rotate the token after suspected exposure, and prefer a version that supports Authorization-header authentication if the provider offers one.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:260
Finding

Authentication Token Exposed in URL Query String

Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` All query parameters, including the token, are then appended to the request URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } function appendValue(searchParams, name, value) { if (Array.isArray(value)) { for (const item of value) { appendValue(searchParams, name, item); } return; } if (value && typeof value === "object") { searchParams.append(name, JSON.stringify(value)); return; } searchParams.append(name, String(value)); } ``` ### Technical Analysis The Skill legitimately requires network access to the fixed HTTPS host `api.justoneapi.com`, and transmitting an authentication credential is necessary for its declared API functionality. There is no evidence that the token is sent to an undeclared destination or covertly exfiltrate ...[truncated 1874 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and is explicitly designed to call an external API, but it does not declare an explicit tool scope such as permissions or allowed-tools. That mismatch weakens policy enforcement and reviewability because consumers cannot easily tell from the manifest that the skill will perform outbound network access and use a secret token.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill requires an authentication token as a query parameter and injects it into the request URL, which exposes the secret in places where URLs are commonly logged or retained, such as browser history, proxy logs, server access logs, monitoring systems, and error reports. Even though the request uses HTTPS, putting credentials in the URL unnecessarily increases token leakage risk compared with using an Authorization header or another protected channel.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON manifest-like file describes what the skill does but does not define any specific trigger phrases, activation boundaries, or exclusion conditions. In manifest files, that lack of trigger specificity can make it unclear when the skill should activate versus when it should not.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
65% confidence
Finding

The natural-language description is specific to Xiaohongshu Creator Marketplace and uses platform-specific terminology without offering any language or locale choice. If this skill is intended for broader use, the hard-coded locale/platform context may conflict with a policy preferring user choice or explicit justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation requires a user authentication token in a query parameter but provides no warning about secure handling, storage, logging, or privacy implications. Query-string tokens are especially prone to exposure through logs, browser history, analytics, referrers, and intermediary systems, so even documentation-only omissions can encourage unsafe integration patterns.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:49