Back to skill

Security audit

Zhihu Column Article Details API

Security checks for vulnerabilities and agentic risk

Overview

This is a narrow Zhihu article lookup skill, but it handles the JustOneAPI token in a way that can expose it through command arguments and request URLs.

Install only if you are comfortable giving this skill a JustOneAPI token and having that token transmitted to JustOneAPI in the request URL. Use a narrowly scoped or low-risk token if available, avoid shell tracing or logging full commands, restrict access to process and proxy logs, and rotate the token if it may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:23
Finding

API Credential Exposed Through Command-Line Arguments and URL Query String

Content
View full analysis
item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The documented invocation also puts the credential in a command-line argument: ```bash node {baseDir}/bin/run.mjs --operation "getColumnArticleDetailV1" --token "$JUST_ONE_API_TOKEN" --params-json '{"id":""}' ``` ### Technical Analysis The helper accepts the API credential through `--token`, copies it into `params.token`, and treats `token` as a query parameter. The resulting request has the effective form: ```text https://api.justoneapi.com/api/zhihu/get-column-article-detail/v1?token=&id= ``` This creates two credential-exposure surfaces: 1. **Process ...[truncated 2356 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill invokes a network-capable helper (node {baseDir}/bin/run.mjs) and requires an API token, but it does not declare an explicit tool scope such as permissions or allowed-tools. This can cause an agent platform to grant broader capabilities than intended or make the network use insufficiently transparent to reviewers, increasing the risk of unauthorized outbound requests or misuse of secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill requires a secret token and places it in the query string, which becomes part of the full URL. Query parameters are commonly exposed in logs, browser history, proxy/CDN telemetry, monitoring systems, and error reports, so the token can be unintentionally disclosed even when HTTPS is used.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest-style file describes what the skill does, but it provides no explicit activation conditions, trigger phrases, or exclusion conditions. For manifest files, missing specificity on when the skill should activate can cause unintended invocation because the skill is broadly described only by its capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API requires a token in a query parameter but provides no user-facing warning, disclosure, or safer authentication guidance. Query-string tokens are commonly exposed in logs, browser history, intermediary systems, and telemetry, increasing the risk of credential leakage and unauthorized API use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file describes fetching full Zhihu article details, including content, and requires a token parameter, but it provides no user warning about privacy, authorization, or safe handling of retrieved content and credentials. For markdown files, omitted warnings about behaviors affecting user data or privacy should be flagged.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:41