Back to skill

Security audit

Google SERP Patents Search API

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it passes the Just Serp API key in a way that can expose it locally.

Review before installing. Use this only if you are comfortable giving it a Just Serp API key for calls to api.justserpapi.com, and prefer a version that reads the key from the environment or a secret manager instead of passing it as a command-line argument.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:295
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:57,65; bin/run.mjs:213,228,295-296
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

SKILL.md:57:

bash
node {baseDir}/bin/run.mjs --operation "patentSearch" --api-key "$JUST_SERP_API_KEY" --params-json '{"query":"<query>"}'

SKILL.md:65:

markdown
- Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs.

bin/run.mjs:211-214:

js
if (!args.apiKey) {
  fail("Missing required --api-key argument.");
}

bin/run.mjs:225-231:

js
const requestInit = {
  headers: {
    "accept": "application/json",
    "X-API-Key": args.apiKey,
  },
  method: operation.method,
};

bin/run.mjs:294-299:

js
if (flag === "--api-key") {
  parsed.apiKey = value;
  index += 1;
  continue;
}

Technical Analysis

The documented invocation expands JUST_SERP_API_KEY into the argument vector of the Node.js process. The implementation then reads the expanded credential from process.argv and places it in the X-API-Key request header.

Passing secrets as command-line arguments is unsafe because process arguments may be observable through operating-system process inspection interfaces, monitoring agents, diagnostic tooling, command auditing, or crash-report collection. The documentation's instruction not to paste or log the key does not prevent these system-level disclosure channels.

The outbound request itself uses HTTPS and targets the fixed, declared domain api.justserpapi.com; the issue is the local credential transport mechanism rather than plaintext network transmission.

Attack Path

  1. A victim exports a valid JUST_SERP_API_KEY.
  2. The victim runs the documented command with --api-key "$JUST_SERP_API_KEY".
  3. The shell expands the environ ...[truncated 1186 chars]
Remediation
View remediation

Remediation Suggestions

  1. Read the credential directly from the environment instead of accepting it as a command-line argument:

    js
    const apiKey = process.env.JUST_SERP_API_KEY;
    
    if (!apiKey) {
      fail("Missing required JUST_SERP_API_KEY environment variable.");
    }
    
  2. Replace args.apiKey with the environment-derived value when constructing the request:

    js
    const requestInit = {
      headers: {
        accept: "application/json",
        "X-API-Key": apiKey,
      },
      method: operation.method,
    };
    
  3. Remove --api-key parsing and update SKILL.md so the documented invocation does not place the credential in the argument vector:

    bash
    JUST_SERP_API_KEY="$JUST_SERP_API_KEY" node {baseDir}/bin/run.mjs \
      --operation "patentSearch" \
      --params-json '{"query":"<query>"}'
    

    When the variable is already exported, omit the inline assignment entirely.

  4. If environment-based secret delivery is unsuitable, accept the credential through protected standard input or an operating-system secret manager. Do not print, serialize, or include the credential in errors.

  5. Rotate any API key that may already have been captured by process telemetry, shell auditing, monitoring agents, or diagnostic logs.

  6. Add regression tests confirming that secrets are absent from process.argv, standard output, standard error, and generated error payloads.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and relies on an external API key, but it does not explicitly declare tool scope such as permissions or allowed-tools. This creates an authorization ambiguity where a host agent may permit broader network execution than reviewers or policy systems can easily validate, increasing the risk of unintended outbound requests or misuse of secrets.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is described as a patent-search interface, but it also exposes a scholar parameter that can retrieve Google Scholar results, expanding behavior beyond the declared scope. This kind of scope mismatch can bypass user or policy expectations, cause unintended data retrieval, and weaken trust or downstream authorization assumptions about what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.