Back to skill

Security audit

Google SERP Maps Photos API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a focused Just Serp API wrapper, but its documented command passes the API key as a process argument that may be exposed locally.

Review before installing if the Just Serp API key is sensitive or high-value. Prefer a version that reads JUST_SERP_API_KEY directly from the environment or another protected secret source instead of passing it as --api-key on the command line.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:164
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis
"}' ``` ### Technical Analysis The shell expands `$JUST_SERP_API_KEY` before starting Node.js, placing the plaintext API key in the new process's argument vector. Depending on operating-system access controls and the execution environment, command-line arguments may be visible through process inspection interfaces, process-monitoring agents, audit logs, debugging tools, shell tracing, or orchestration telemetry. Although the key is subsequently sent to the intended service through the `X-API-Key` HTTPS header, accepting it through `--api-key` creates an unnecessary local disclosure channel. This also conflicts with the documentation's stated goal of preventing API keys from appearing in logs. ### Attack Path 1. A victim follows the documented command and supplies `JUST_SERP_API_KEY` through `--api-key`. 2. The shell expands the environment variable into the plaintext process argument vector. 3. While the helper is running, an attacker or monitoring compone ...[truncated 968 chars]
Remediation
View remediation
"}' ``` Where possible, inject the environment variable through a secret manager or protected runtime configuration rather than defining it inline. 4. Reject `--api-key` explicitly so users do not continue exposing credentials through legacy commands. 5. Avoid logging request headers, environment values, or complete process arguments. 6. Rotate any API key that may previously have been captured through process monitoring, command auditing, or shell tracing. 7. If environment-based secret injection is unavailable, accept the secret through protected standard input or an operating-system secret store rather than through command-line arguments. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) that can make outbound API requests, but the manifest does not explicitly declare any tool scope such as permissions or allowed-tools. This creates a policy gap where consumers or runtimes cannot clearly constrain or review the skill’s external communication behavior, increasing the risk of unexpected data egress or overbroad execution in permissive environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.