Back to skill

Security audit

Google SERP Ai Mode API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Just Serp API wrapper, but it handles the API key through command-line arguments, which can expose the credential locally.

Review before installing. Use this only if you are comfortable sending search queries and optional location fields to Just Serp API, avoid sensitive queries unless necessary, and prefer a version that reads JUST_SERP_API_KEY directly from the environment instead of passing the key with --api-key.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:188
Finding

API Key Exposed Through Process Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:46,52; bin/run.mjs:105-107,188-192
Vulnerability Type: API key exposure through process arguments
Risk Level: Medium

The documented invocation passes the Just Serp API key as a command-line argument:

bash
node {baseDir}/bin/run.mjs --operation "aiMode" --api-key "$JUST_SERP_API_KEY" --params-json '{"query":"<query>"}'

The documentation explicitly directs users to use the affected argument:

markdown
- Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs.

The executable requires and parses that argument:

js
if (!args.apiKey) {
  fail("Missing required --api-key argument.");
}
js
if (flag === "--api-key") {
  parsed.apiKey = value;
  index += 1;
  continue;
}

Technical Analysis

Although the key originates in an environment variable, shell expansion places its value directly in the Node process argument vector. Depending on operating-system configuration, command-line arguments can be observed through process-listing utilities, process metadata interfaces, diagnostic tools, monitoring agents, shell tracing, or command-execution logs.

The implementation does not print the key itself, and it sends the credential only to the fixed HTTPS API endpoint. Nevertheless, using an argument for secret transport unnecessarily increases local exposure compared with reading the existing JUST_SERP_API_KEY environment variable directly.

Exploitation requires local process-observation access or access to tooling that records command lines. No evidence was found that this issue enables remote code execution, privilege escalation, persistence, or arbitrary access to unrelated credentials.

Attack Path

  1. A user exports a valid value in JUST_SERP_API_KEY.
  2. The user invokes the helper using the command documented in SKILL.md.
  3. The ...[truncated 902 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove --api-key from the documented invocation and read the declared environment variable directly:

    js
    const apiKey = process.env.JUST_SERP_API_KEY;
    
    if (!apiKey) {
      fail("Missing required JUST_SERP_API_KEY environment variable.");
    }
    
  2. Use apiKey only when constructing the request header:

    js
    const requestInit = {
      headers: {
        accept: "application/json",
        "X-API-Key": apiKey,
      },
      method: operation.method,
    };
    
  3. Remove API-key handling from parseArgs so the secret cannot accidentally be supplied through the process argument vector.

  4. Update SKILL.md to use the following form:

    bash
    JUST_SERP_API_KEY="$JUST_SERP_API_KEY" node {baseDir}/bin/run.mjs --operation "aiMode" --params-json '{"query":"<query>"}'
    

    Prefer invoking the command from an environment where the variable is already exported, avoiding redundant assignment on the command line.

  5. Ensure errors, debug output, telemetry, and request logging never serialize request headers or the environment variable.

  6. Rotate any API key that may already have been captured by process-monitoring or command-recording systems, and review account usage for unauthorized requests.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill clearly enables outbound network access to a third-party API via the provided Node helper, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a policy and containment gap: an agent runtime may permit broader-than-intended network behavior or fail to present users with clear authorization boundaries for external data transmission. In this context, user queries and localization parameters are sent to an external service, so undeclared network capability increases privacy and governance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs a network request to a third-party service and includes user-provided search terms and optional location parameters in the request URL. While the behavior is functional, there is no confirmation prompt, visible notice, or explanatory comment/docstring warning that user input and localization data will be sent off-system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This skill sends user-provided search queries and optional location/localization data such as country, location, and UULE to a third-party API, but the manifest provides no user-facing disclosure about that external data sharing or its privacy implications. Because search queries can contain sensitive personal, medical, financial, or workplace information, and localization fields can further increase identifiability, the lack of transparency and consent is a meaningful privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation explicitly exposes options to return raw HTML and highly localized search data (country, UULE, location) without warning about privacy, sensitive data collection, or downstream handling risks. In an agent skill context, this can lead integrators to collect or transmit user location-linked search data and full page content without informed consent, increasing privacy leakage and data minimization failures.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.