Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) Note Details API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow JustOneAPI wrapper, but it passes the user's API token in a URL query parameter, which can expose credentials in logs or telemetry.

Review before installing if your JustOneAPI token has broad permissions, billing impact, or long lifetime. Use a scoped, revocable token if possible, avoid placing the token in chat or logs, and be aware that this skill sends the token and noteId to JustOneAPI with the token embedded in the request URL.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:20
Finding

Authentication Token Transmitted in URL Query String

Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } function appendValue(searchParams, name, value) { if (Array.isArray(value)) { for (const item of value) { appendValue(searchParams, name, item); } return; } if (value && typeof value === "object") { searchParams.append(name, JSON.stringify(value)); return; } searchParams.append(name, String(value)); } ``` ### Technical Analysis The operation manifest explicitly classifies the authentication token as a query parameter. The helper copies the supplied ...[truncated 2754 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill invokes a network-capable helper (node {baseDir}/bin/run.mjs ...) but does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap: a host agent may not have enough metadata to constrain or review outbound network use, increasing the chance of unintended external requests with user-supplied data and secrets-adjacent context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill sends the authentication token as a URL query parameter (token), which is then embedded in the full request URL. Query-string secrets are commonly exposed through logs, browser/history tooling, proxies, monitoring systems, and error telemetry, making accidental credential disclosure much more likely even when HTTPS is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill requires a user authentication token and noteId to be sent to an external third-party API, but the manifest does not clearly warn users about that data transfer. This can lead to inadvertent disclosure of sensitive credentials or identifiers to an external service, especially if users assume the data stays within the local platform or first-party environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This manifest-style JSON describes what the skill does but provides no explicit trigger phrases, invocation constraints, or exclusion conditions. For manifest files, the absence of specific activation scope can make invocation behavior ambiguous if downstream systems derive triggers from broad descriptions.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:42