Back to skill

Security audit

Xiaohongshu Creator Marketplace (Pugongying) API

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate Xiaohongshu/Pugongying JustOneAPI wrapper, but it handles API tokens in URLs and command arguments in a way users should review before installing.

Install only if you are comfortable giving this skill a JustOneAPI token for Xiaohongshu/Pugongying analytics. Treat the token as sensitive, prefer short-lived or scoped tokens if available, avoid running it where command arguments or URLs are logged, and review logs if a token was already used with this runner.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:1481
Finding

API Token Exposed Through Command-Line Arguments and URL Query Parameters

Content
View full analysis
" --token "$JUST_ONE_API_TOKEN" --params-json '{"key":"value"}' ``` `bin/run.mjs:1481-1503`: ```javascript injectToken(operation, params, args.token); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", }, method: operation.method, }; if (operation.requestBody && params.body !== undefined) { requestInit.body = JSON.stringify(params.body); requestInit.headers["content-type"] = operation.requestBody.contentType || "application/json"; } let response; try { response = await fetch(url, requestInit); ``` `bin/run.mjs:1558-1559`: ```javascript if (flag === "--token") { parsed.token = value; ``` `bin/run.mjs:1590-1600`: ```javascript function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; ``` `bin/run.mjs:1637-1651`: ```javascript function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } func ...[truncated 3576 chars]
Remediation
View remediation
" \ --params-json '{"key":"value"}' ``` 6. **Credential response** - Rotate tokens that may already have appeared in process telemetry, shell traces, proxy logs, or URL access logs. - Review retained logs for unauthorized disclosure and subsequent token use. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
- Get a token from [Just One API Dashboard](https://dashboard.justoneapi.com/en/login?utm_source=clawhub.ai&utm_medium=referral&utm_campaign=justoneapi_xiaohongshu_pgy&utm_content=project_link).
- Authentication details: [Just One API Usage Guide](https://docs.justoneapi.com/en/?utm_source=clawhub.ai&utm_medium=referral&utm_campaign=justoneapi_xiaohongshu_pgy&utm_content=project_link).

## Output Rules

- Start with a plain-language answer tied to the Xiaohongshu Creator Marketplace (Pugongying) task the user asked for.
- Include the most decision-relevant fields from the selected endpoint before dumping raw JSON.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill invokes a Node helper that performs authenticated API calls, but the manifest does not declare an explicit tool scope such as allowed network access or execution permissions. That mismatch weakens least-privilege controls and can let a host agent expose broader execution/network capability than reviewers or policy engines expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill requires the authentication token to be sent as a query parameter, and the runner automatically appends it to the URL. Query-string credentials are commonly exposed through logs, browser/history tooling, proxies, analytics, error reporting, and upstream infrastructure, making credential leakage significantly more likely even when HTTPS is used. In this skill context, the token grants access to creator marketplace and audience analytics APIs, so leakage could enable unauthorized access to account-scoped data or quota abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

On request failures and invalid-JSON responses, the code writes backend response bodies directly to stderr via fail(...), which can disclose sensitive API data into terminal output, CI logs, agent traces, or centralized logging systems. Because this skill interacts with authenticated creator and audience analytics endpoints, error bodies may contain tokens, identifiers, profile data, or diagnostic details that should not be broadly exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documentation repeatedly requires authentication tokens in query parameters and describes access to creator, follower, audience, and pricing data, yet provides no warning about handling secrets or sensitive personal and analytics data. Without clear privacy and token-handling guidance, integrators may log tokens in URLs, leak them through telemetry or browser history, and process personal or commercial data without appropriate safeguards.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented operations materially exceed the stated skill description, exposing creator search, note detail, audience profiling, pricing, and benchmarking capabilities beyond the narrower advertised scope. This mismatch can mislead users and downstream policy controls about what data the skill can access and process, increasing the risk of unintended collection or use of sensitive creator and audience information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language description and display name are exclusively framed around Xiaohongshu Creator Marketplace (Pugongying), a Chinese platform context, but the file does not state whether this locale-specific scope is intentional, optional, or user-selected. Under the policy rule, locale constraints should either offer user choice or be clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.