T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:157- Finding
API Key Exposed Through Process Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a narrow Just Serp API wrapper for Google Maps place details, with a minor credential-handling caution but no hidden or destructive behavior found.
Install only if you are comfortable giving the skill a Just Serp API key and allowing it to call the documented Just Serp endpoint. Prefer rotating the key if it has been used in environments that log process arguments, and avoid running with shell tracing or command auditing that records secrets.
bin/run.mjs:157API Key Exposed Through Process Command-Line Arguments
The skill invokes a network-capable helper (node .../run.mjs) but does not declare an explicit tool scope such as permissions or allowed-tools. This creates a governance gap: an agent platform may permit broader execution or fail to clearly constrain/communicate that the skill performs outbound API calls using a secret-backed credential, increasing the chance of unintended external requests or misuse.
No suspicious patterns detected.