Back to skill

Security audit

Google SERP Patents Details API

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to call the advertised patent-details API, but it passes the API key on the command line, which can expose the secret locally.

Review before installing if the Just Serp API key has paid quota or broad account access. Prefer a version that reads JUST_SERP_API_KEY inside the helper instead of passing it as --api-key, and run it only in environments where command lines are not captured in logs or visible to other local users.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 42
Related Code: bin/run.mjs, lines 89–91 and 147–162
Vulnerability Type: API credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

bash
node {baseDir}/bin/run.mjs --operation "patentDetails" --api-key "$JUST_SERP_API_KEY" --params-json '{"patent_id":"<patent_id>"}'

The helper parses the expanded credential from the command line and places it in an HTTP header:

js
const requestInit = {
  headers: {
    "accept": "application/json",
    "X-API-Key": args.apiKey,
  },
  method: operation.method,
};
js
if (flag === "--api-key") {
  parsed.apiKey = value;
  index += 1;
  continue;
}

Technical Analysis

Although the credential originates in the JUST_SERP_API_KEY environment variable, the documented command expands its value into the Node.js process argument vector. Command-line arguments can be exposed through process-inspection interfaces, diagnostic and monitoring tools, shell tracing, audit systems, or logs that record complete commands.

The implementation requires this insecure credential transport instead of reading the already-declared environment variable inside the process. Exploitation requires local process-observation capability or access to telemetry that captures command lines; no remote exploitation path was identified.

Attack Path

  1. A victim configures JUST_SERP_API_KEY and invokes the helper using the documented command.
  2. The shell expands "$JUST_SERP_API_KEY" into the value supplied to --api-key.
  3. The secret becomes part of the Node.js process argument vector.
  4. A local user, monitoring component, audit collector, or diagnostic tool with permission to inspect command lines captures the argument.
  5. The observer extracts and reuses the API key against the Just Serp API.

Impact Assessment

Successful exploitation discloses the Just Serp API credential. An attacker could make authenticated ...[truncated 382 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the --api-key command-line option and read the declared environment variable directly:
js
const apiKey = process.env.JUST_SERP_API_KEY;
if (!apiKey) {
  fail("Missing required JUST_SERP_API_KEY environment variable.");
}
  1. Use the internally loaded value only when constructing the request header:
js
const requestInit = {
  headers: {
    accept: "application/json",
    "X-API-Key": apiKey,
  },
  method: operation.method,
};
  1. Update the documented invocation so the secret is not included in the argument vector:
bash
node {baseDir}/bin/run.mjs --operation "patentDetails" --params-json '{"patent_id":"<patent_id>"}'
  1. If explicit credential injection is required, use standard input or a permission-restricted credential source rather than process arguments.

  2. Ensure application logs, shell tracing, diagnostics, and error output never record API-key values. Rotate any credential that may previously have been exposed through command-line capture.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs the agent to invoke a network-capable helper (node ... run.mjs) and use an external API key, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates a policy gap where an agent runtime may permit broader-than-intended network access or make review of outbound capabilities harder, increasing the risk of unintended external requests and data exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.