Back to skill

Security audit

Google SERP Immersive Product API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrowly scoped helper for one Just Serp API endpoint, with a credential-handling caveat users should understand before running it.

Install only if you intend to use Just Serp API and are comfortable sending page_token query parameters and your Just Serp API key to api.justserpapi.com. Prefer a version that reads the key directly from the environment or another protected secret channel instead of passing it as --api-key on the command line.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:187
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:45-53, bin/run.mjs:104-105, bin/run.mjs:118-121, and bin/run.mjs:187-190
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

bash
node {baseDir}/bin/run.mjs --operation "immersiveProduct" --api-key "$JUST_SERP_API_KEY" --params-json '{"page_token":"<page_token>"}'
js
if (!args.apiKey) {
  fail("Missing required --api-key argument.");
}
js
const requestInit = {
  headers: {
    "accept": "application/json",
    "X-API-Key": args.apiKey,
  },
  method: operation.method,
};
js
if (flag === "--api-key") {
  parsed.apiKey = value;
  index += 1;
  continue;
}

Technical Analysis

The documented invocation expands JUST_SERP_API_KEY into the Node process argument vector. The argument parser then requires and consumes the key through --api-key.

Command-line arguments may be captured by process-inspection interfaces, monitoring or observability agents, shell auditing, diagnostic reports, and command-history mechanisms. Consequently, the documentation's warning not to paste or log the key does not prevent disclosure through the process command line itself.

This issue requires an attacker or monitoring system capable of observing command invocation data. It does not independently grant remote code execution or elevated operating-system privileges.

Attack Path

  1. A user follows the documented command and invokes the helper with --api-key "$JUST_SERP_API_KEY".
  2. The shell expands the environment variable before starting Node, placing the plaintext key in the child process argument vector.
  3. A local user, privileged process-monitoring service, audit facility, or diagnostic collector records or reads the command-line arguments.
  4. The observer extracts the API key.
  5. The observer submits the stolen key in the X-API-Key header to Just Serp API endpoints.
  6. The observer can consume the v ...[truncated 573 chars]
Remediation
View remediation

Remediation Suggestions

  1. Read the credential directly from the process environment rather than accepting it as a command-line argument:
js
const apiKey = process.env.JUST_SERP_API_KEY;

if (!apiKey) {
  fail("Missing required JUST_SERP_API_KEY environment variable.");
}
  1. Use the environment-derived value when constructing the request:
js
const requestInit = {
  headers: {
    accept: "application/json",
    "X-API-Key": apiKey,
  },
  method: operation.method,
};
  1. Remove or deprecate --api-key handling so secrets cannot accidentally be supplied in process arguments.
  2. Update the documented invocation to omit the credential argument:
bash
JUST_SERP_API_KEY="..." node {baseDir}/bin/run.mjs \
  --operation "immersiveProduct" \
  --params-json '{"page_token":"<page_token>"}'
  1. Where environment visibility is also a concern, support credential input through a protected file descriptor, standard input, or an operating-system secret manager.
  2. Ensure errors, debug output, telemetry, and request logging never serialize the API key or complete request headers.
  3. Rotate any key suspected of having been captured by process monitoring, command auditing, or diagnostic tooling.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and is explicitly designed to call an external API, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a governance gap: a host platform or reviewer cannot clearly enforce or validate that the skill is only expected to use network access, increasing the risk of unintended or overly broad tool usage when executed in an agent environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends the provided X-API-Key credential in an outbound HTTP request to api.justserpapi.com, but there is no confirmation prompt, user-facing log message, or explanatory comment/docstring warning that credentials and request parameters will be transmitted externally. For a code file, outbound network transmission of credentials or user/system data should include some visible disclosure unless already clearly warned elsewhere.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This JSON file is a manifest-style interface description, so vague-trigger checks apply. The description and display name describe what the skill does, but they do not specify any explicit invocation phrases, constraints, or negative examples, leaving activation scope ambiguous if this metadata is used for routing or tool selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.