Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Note Performance Metrics API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrowly scoped API wrapper for one JustOneAPI Xiaohongshu metrics endpoint, with the main risk being ordinary API-token handling exposure rather than hidden or unrelated behavior.

Install only if you are comfortable sending a JustOneAPI token and the requested kolId to api.justoneapi.com. Prefer a narrowly scoped, revocable token, avoid putting real token values in chat or logs, and rotate the token if you suspect command history, process monitoring, proxy logs, or server logs captured it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:218
Finding

API Token Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
"}' ``` The helper accepts the token from the command line: ```js function parseArgs(argv) { const parsed = { operation: null, paramsJson: "{}", token: null }; for (let index = 0; index < argv.length; index += 1) { const flag = argv[index]; const value = argv[index + 1]; if (flag === "--operation") { parsed.operation = value; index += 1; continue; } if (flag === "--params-json") { parsed.paramsJson = value; index += 1; continue; } if (flag === "--token") { parsed.token = value; index += 1; continue; } fail(`Unknown argument "${flag}".`); } return parsed; } ``` It then adds that token to the operation parameters: ```js function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` All query parameters, including `token`, are serialized into the request URL: ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } function appendValue(s ...[truncated 2686 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a network-capable helper (node .../run.mjs) and is explicitly designed to call a remote API, but it does not declare an explicit tool scope such as permissions or allowed-tools. That mismatch weakens least-privilege controls and can cause the runtime or reviewer to underestimate the skill’s external communication capabilities, increasing the risk of unintended data exfiltration or unauthorized outbound requests if the skill is reused or modified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This script performs an outbound HTTP request and includes a required token query parameter, which is user authentication data. While the code validates and injects the token, it provides no confirmation prompt, visible disclosure, or explanatory comment/docstring warning that credentials will be sent to api.justoneapi.com.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This manifest-style JSON describes what the skill does but provides no explicit activation phrases, exclusion conditions, or context constraints. In manifest files, that absence can make invocation behavior ambiguous because there is no indication of when the skill should or should not be selected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

All user-facing text in the file is fixed in English even though the skill targets Xiaohongshu/Pugongying, a platform likely used in other locales. Under the stated policy, forcing a specific language without opt-in can be a locale-policy issue when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:50