Back to skill

Security audit

Xiaohongshu (RedNote) Share Link Resolution API

Security checks for vulnerabilities and agentic risk

Overview

This is a focused JustOneAPI RedNote link resolver, with the main caution that its API token is sent as a URL query parameter.

Install only if you are comfortable sending the RedNote share URL and your JustOneAPI token to JustOneAPI. Use the narrowest token available, avoid pasting it into chat or logs, and rotate it if it may have been exposed, because this runner places the token in the request URL query string.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:31
Finding

API Access Token Exposed in URL Query String

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:31-38, 73-80, 92-96, 216-225
Vulnerability Type: Sensitive credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

js
{
  "defaultValue": null,
  "description": "Access token for this API service.",
  "enumValues": [],
  "location": "query",
  "name": "token",
  "required": true,
  "schemaType": "string"
}
js
const params = parseParams(args.paramsJson);
applyDefaults(operation, params);
injectToken(operation, params, args.token);
validateRequired(operation, params);

const baseUrl = manifest.baseUrl;
const url = new URL(operation.path, ensureBaseUrl(baseUrl));
applyPathParams(operation, params, url);
applyQueryParams(operation, params, url);
js
let response;
try {
  response = await fetch(url, requestInit);
} catch (error) {
  fail("Network request failed.", {
    cause: error instanceof Error ? error.message : String(error),
    operationId: operation.operationId,
  });
}
js
function applyQueryParams(operation, params, url) {
  for (const parameter of operation.parameters.filter((item) => item.location === "query")) {
    const value = params[parameter.name];
    if (value === undefined) {
      continue;
    }
    appendValue(url.searchParams, parameter.name, value);
  }
}

Technical Analysis

The operation manifest classifies the API access token as a query parameter. The program copies the token supplied through --token into params.token, after which applyQueryParams() serializes it into url.searchParams. The resulting request has the effective form:

text
https://api.justoneapi.com/api/xiaohongshu/share-url-transfer/v1?token=<credential>&shareUrl=<user-input>

HTTPS protects the request from passive interception while it is in transit, but it does not prevent the complete URL from being retained by the de ...[truncated 2136 chars]

Remediation
View remediation

Remediation Suggestions

  1. Change the API authentication contract to accept the credential in an authorization header rather than the URL:

    js
    const requestInit = {
      headers: {
        accept: "application/json",
        authorization: `Bearer ${args.token}`,
      },
      method: operation.method,
    };
    
  2. Remove token from the operation's query-parameter definition and ensure applyQueryParams() cannot serialize authentication credentials:

    js
    function applyQueryParams(operation, params, url) {
      for (const parameter of operation.parameters.filter(
        (item) => item.location === "query" && item.name !== "token"
      )) {
        const value = params[parameter.name];
        if (value !== undefined) {
          appendValue(url.searchParams, parameter.name, value);
        }
      }
    }
    
  3. Prefer reading the token directly from JUST_ONE_API_TOKEN instead of requiring it as a command-line argument. Command-line values may be visible in process listings, shell history, job telemetry, or orchestration metadata.

  4. Redact tokens, authorization headers, and sensitive query parameters from application logs, proxy logs, exception reports, distributed traces, and monitoring telemetry.

  5. If the remote API only supports query-string authentication, document this residual risk explicitly, use narrowly scoped and short-lived tokens, rotate credentials regularly, and configure every involved proxy and server not to retain query strings.

  6. Update SKILL.md, generated/operations.json, and generated/operations.md after changing the authentication contract so the documentation and generated metadata remain consistent with the hardened implementation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill explicitly exposes an access token input and places it in a GET request query parameter, creating a credential-handling pattern with elevated leakage risk. In the context of an agent skill, this is more dangerous because agent frameworks may surface, persist, or replay parameter values in logs, debugging output, or telemetry, increasing the chance of credential disclosure and unauthorized API use.

Content

Scanner excerpt · generated/operations.json (reported line 15)May include surrounding context.

json
"parameters": [
        {
          "defaultValue": null,
          "description": "Access token for this API service.",
          "enumValues": [],
          "location": "query",
          "name": "token",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/run.mjs (reported line 20)May include surrounding context.

js
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `shareUrl` | `query` | yes | `string` | n/a | RedNote share link URL to be resolved (short link or shared URL). |

### Request body

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generated/operations.md (reported line 19)May include surrounding context.

md
| Name | In | Required | Type | Default | Description |
| --- | --- | --- | --- | --- | --- |
| `token` | `query` | yes | `string` | n/a | Access token for this API service. |
| `shareUrl` | `query` | yes | `string` | n/a | RedNote share link URL to be resolved (short link or shared URL). |

### Request body

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a network-capable helper to call an external API, but it does not declare an explicit tool scope such as allowed-tools or permissions. This weakens sandboxing and reviewability because the runtime may permit outbound requests without a narrowly documented capability boundary, increasing the chance of unintended data egress or misuse if the skill is extended or interpreted loosely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill defines the API access token as a query parameter and later appends all query parameters directly to the URL. Tokens in URLs are commonly exposed through logs, browser/history equivalents, proxies, monitoring systems, and error messages, making accidental credential disclosure more likely even when HTTPS is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The API requires an access token as a query parameter, but the specification provides no warning about secure handling, logging, or transmission risks. Query parameters are commonly captured in logs, proxies, analytics, browser history, and observability tooling, which can expose credentials beyond their intended scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The shareUrl parameter is described as a user-supplied RedNote share link, and the code transmits all query parameters to https://api.justoneapi.com via fetch. Although network access is central to the skill's purpose, this file contains no disclosure that user-provided URLs are sent to a third-party service.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest-style JSON describes what the skill does, but it provides no explicit invocation phrases, scope limits, or exclusion conditions. In manifest files, the absence of specific trigger constraints can make activation behavior ambiguous and increases the risk of unintended invocation if external tooling derives triggers from broad descriptions.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:41