Back to skill

Security audit

Google SERP Jobs Search API

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but its recommended command exposes the Just Serp API key in process arguments, so users should review that credential-handling risk before installing.

Install only if you are comfortable sending job-search queries and filters to Just Serp API. Treat the documented --api-key invocation as risky: prefer a version that reads JUST_SERP_API_KEY directly from the environment or another protected secret channel instead of placing the key in command-line arguments.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:223
Finding

API Key Exposed Through Process Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:49,57; bin/run.mjs:139-141,156,223-226
Vulnerability Type: API credential exposure through process arguments
Risk Level: Medium

The documented invocation passes the Just Serp API key through the --api-key command-line argument:

bash
node {baseDir}/bin/run.mjs --operation "jobsSearch" --api-key "$JUST_SERP_API_KEY" --params-json '{"query":"<query>"}'

The script requires, parses, and uses that argument as follows:

js
if (!args.apiKey) {
  fail("Missing required --api-key argument.");
}
js
const requestInit = {
  headers: {
    "accept": "application/json",
    "X-API-Key": args.apiKey,
  },
  method: operation.method,
};
js
if (flag === "--api-key") {
  parsed.apiKey = value;
  index += 1;
  continue;
}

Technical Analysis

Although the documentation obtains the credential from the JUST_SERP_API_KEY environment variable, the shell expands "$JUST_SERP_API_KEY" before starting Node.js. The plaintext credential consequently becomes part of the process argument vector.

Process arguments may be visible through operating-system process inspection interfaces, diagnostic utilities, monitoring agents, crash reports, audit logs, or command telemetry. An observer with sufficient local process-inspection access could capture the API key while the helper is running. The documentation's warning not to place the key in logs does not prevent this exposure because the recommended command itself transfers the secret into argv.

Attack Path

  1. A user stores a valid Just Serp API credential in JUST_SERP_API_KEY.
  2. The user invokes the helper using the command documented in SKILL.md.
  3. The shell expands the environment variable and places the plaintext key after --api-key in the Node.js process argument vector.
  4. A local process observer, privileged monitoring component, or diagnost ...[truncated 694 chars]
Remediation
View remediation

Remediation Suggestions

  1. Read the credential directly from the environment instead of accepting it through a command-line argument:

    js
    const apiKey = process.env.JUST_SERP_API_KEY;
    
    if (!apiKey) {
      fail("Missing required JUST_SERP_API_KEY environment variable.");
    }
    
  2. Use the environment-derived value when constructing the request:

    js
    const requestInit = {
      headers: {
        accept: "application/json",
        "X-API-Key": apiKey,
      },
      method: operation.method,
    };
    
  3. Remove --api-key handling from parseArgs so callers cannot inadvertently expose credentials through argv.

  4. Update the documented invocation to omit the credential argument:

    bash
    JUST_SERP_API_KEY="$JUST_SERP_API_KEY" node {baseDir}/bin/run.mjs \
      --operation "jobsSearch" \
      --params-json '{"query":"<query>"}'
    
  5. If explicit secret input is required, accept it through protected standard input, a dedicated secret manager, or a permission-restricted credential file rather than command-line arguments.

  6. Avoid logging request headers, environment variables, or credential-bearing configuration. Redact X-API-Key in diagnostic and error-reporting systems.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a network-capable helper (node {baseDir}/bin/run.mjs) that performs an external API request, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates a governance gap: the runtime may permit broader outbound access than reviewers or policy engines expect, increasing the risk of unintended or abused network operations if the skill is modified or composed with other behaviors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code constructs an outbound HTTP request to a third-party endpoint and includes both user-provided query data and the API credential in headers. There is no confirmation prompt, user-facing log/print, or explanatory comment/docstring in this file warning that input data will be sent off-box to an external API.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.