Back to skill

Security audit

Google SERP Maps Posts API

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to call the stated Just Serp endpoint, but it passes the API key through command-line arguments where it can be locally exposed.

Install only if you are comfortable sending requested Google Maps identifiers to Just Serp and using a Just Serp API key. Prefer a revised version that reads JUST_SERP_API_KEY directly from the environment or a secret store instead of passing it as --api-key, and restrict outbound access to api.justserpapi.com where possible.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:69
Finding

API Key Exposed Through Process Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:44, SKILL.md:49, bin/run.mjs:69-71, and bin/run.mjs:86
Vulnerability Type: Credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

SKILL.md:44:

bash
node {baseDir}/bin/run.mjs --operation "mapsPosts" --api-key "$JUST_SERP_API_KEY" --params-json '{"data_id":"<data_id>"}'

SKILL.md:49:

markdown
- Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs.

bin/run.mjs:69-71:

js
if (!args.apiKey) {
  fail("Missing required --api-key argument.");
}

bin/run.mjs:83-89:

js
const requestInit = {
  headers: {
    "accept": "application/json",
    "X-API-Key": args.apiKey,
  },
  method: operation.method,
};

Technical Analysis

The documented invocation expands JUST_SERP_API_KEY into the --api-key command-line argument before Node starts. Consequently, the plaintext credential becomes part of the process argument vector.

On systems where process metadata is visible to other users, administrators, monitoring agents, diagnostic collectors, audit tooling, or process supervisors, the key may be captured through process-list inspection or command-line telemetry. Although the script does not deliberately print the key and transmits it only to the declared HTTPS API endpoint, using an argument as the credential transport unnecessarily increases its local exposure.

The executable requires args.apiKey and places that value in the X-API-Key request header. The security issue is not the authenticated HTTPS header itself; it is the earlier delivery of the secret through a command-line argument.

Attack Path

  1. A legitimate user launches the documented command with --api-key "$JUST_SERP_API_KEY".
  2. The shell expands the environment variable into its plaintext value.
  3. The expanded key ...[truncated 1144 chars]
Remediation
View remediation

Remediation Suggestions

  1. Read the credential directly from the environment rather than requiring it as a command-line argument:

    js
    const apiKey = process.env.JUST_SERP_API_KEY;
    
    if (!apiKey) {
      fail("Missing required JUST_SERP_API_KEY environment variable.");
    }
    
    const requestInit = {
      headers: {
        accept: "application/json",
        "X-API-Key": apiKey,
      },
      method: operation.method,
    };
    
  2. Remove support for --api-key from parseArgs so users are not encouraged to expose credentials through the process argument vector.

  3. Update the documented command to omit the credential argument:

    bash
    JUST_SERP_API_KEY="..." node {baseDir}/bin/run.mjs \
      --operation "mapsPosts" \
      --params-json '{"data_id":"<data_id>"}'
    

    Prefer setting the variable through the user's protected environment or secret manager rather than placing the assignment directly in interactive shell history.

  4. If an explicit credential channel is necessary, accept it through protected standard input, an operating-system secret store, or a permission-restricted credential file.

  5. Ensure errors, debug logs, telemetry, and exception objects never include the key or complete request headers.

  6. Rotate any credential that may already have been exposed through command-line history, process monitoring, or diagnostic collection.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill describes making outbound API calls and even provides a runnable Node command, but it does not declare an explicit tool scope such as allowed network access. That omission weakens policy enforcement and reviewability because the runtime may permit network behavior that is not clearly constrained or auditable, increasing the chance of unintended external communication or scope creep.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.