Back to skill

Security audit

Google SERP Autocomplete API

Security checks for vulnerabilities and agentic risk

Overview

This is a narrow Just Serp autocomplete API wrapper, but it handles the API key in a way that can expose it through process command lines.

Review this skill before installing if your Just Serp API key has billing or quota value. Prefer a version that reads JUST_SERP_API_KEY directly from the environment instead of passing it with --api-key, and rotate the key if you already used this command in an environment where process arguments are logged or visible.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:82
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis
"}' ``` The implementation requires and parses that command-line argument: ```javascript if (!args.apiKey) { fail("Missing required --api-key argument."); } ``` ```javascript if (flag === "--api-key") { parsed.apiKey = value; index += 1; continue; } ``` ### Technical Analysis Although the key originates in an environment variable, the documented shell command expands its value into the Node process argument vector. Command-line arguments may be visible to other sufficiently privileged local users, process-inspection utilities, monitoring agents, diagnostic systems, container orchestration telemetry, or command-auditing infrastructure. The warning in `SKILL.md` not to paste API keys into logs does not prevent this exposure because the prescribed invocation itself places the plaintext credential in process metadata. The code offers no safer authentication input mechanism, such as reading `JUST_SERP_API_KEY` directly from `process.env` or accepting the credential through protected standard input. ### Attack Path 1. A user configures `JUST_SERP_API_KEY` and invokes the helper using the documented command. 2. The shell expands `$JUST_SERP_API_KEY` into the plaintext `--api-key` argument. 3. While the process is running, or if process execution is recorded, a local observer or monitoring system captures the command line. 4. The observer extracts the API key from the argument following `--api-key`. 5. The exposed credential is replayed against the Just Serp API. Exploitation requires access to process metadata, ...[truncated 638 chars]
Remediation
View remediation
"}' ``` When the environment is already configured, the command should omit the inline assignment entirely. 5. Ensure error messages, debug output, process telemetry, and HTTP diagnostics never serialize the API key or complete request headers. 6. Recommend rotating the API key if it has previously been used through the documented `--api-key` interface in an environment where process arguments are logged or observable. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill invokes a Node helper that performs outbound API requests, but the manifest does not explicitly declare any tool scope such as allowed network access. This creates a permissions/transparency gap: a reviewer or runtime policy engine cannot clearly determine what external communication the skill is expected to perform, which can enable unintended data egress or make abuse harder to detect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code constructs an outbound HTTP request to a third-party API and includes both the user-supplied query parameters and the API key in the request headers. There is no confirmation prompt, user-facing log/print, or inline comment/docstring warning that user input and credentials will be sent off-system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.