Back to skill

Security audit

Google SERP Scholar Cite Search API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a narrow Just Serp API helper, but it passes the API key through command-line arguments where it may be exposed locally.

Review before installing. This skill sends lookup parameters to Just Serp API and requires `JUST_SERP_API_KEY`. Use a version that reads the key directly from the environment instead of `--api-key`, avoid logging command lines, and rotate the key if it may already have appeared in process logs or automation output.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:146
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: bin/run.mjs:79-81, 146-158; documented invocation at SKILL.md:42, 49
Vulnerability Type: API credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

javascript
if (!args.apiKey) {
  fail("Missing required --api-key argument.");
}
javascript
function parseArgs(argv) {
  const parsed = { apiKey: null, operation: null, paramsJson: "{}" };
  for (let index = 0; index < argv.length; index += 1) {
    const flag = argv[index];
    const value = argv[index + 1];

    // Other argument handling omitted.

    if (flag === "--api-key") {
      parsed.apiKey = value;
      index += 1;
      continue;
    }
    fail(`Unknown argument "${flag}".`);
  }
  return parsed;
}

The documented invocation exposes the environment variable through argument expansion:

bash
node {baseDir}/bin/run.mjs --operation "ScholarCiteSearch" --api-key "$JUST_SERP_API_KEY" --params-json '{"query":"<query>"}'

Technical Analysis

The helper requires the API key to be supplied using --api-key, and parseArgs() obtains it from process.argv. Although the secret originates in an environment variable, the shell expands $JUST_SERP_API_KEY before launching Node, placing the plaintext credential in the child process's command-line argument vector.

Depending on operating-system permissions and process isolation, command-line arguments may be observable through facilities such as /proc/<pid>/cmdline, process-listing utilities, monitoring agents, diagnostic tooling, or captured execution telemetry. The request itself uses HTTPS and sends the key in the X-API-Key header; the confirmed weakness is the local credential-transfer mechanism rather than plaintext network transport.

Attack Path

  1. A user stores a valid credential in JUST_SERP_API_KEY.
  2. The user runs the command documented in SKILL.md.
  3. The shell expands $JUST_SERP_API_KEY and places its plaintex ...[truncated 954 chars]
Remediation
View remediation

Remediation Suggestions

  1. Read the credential directly from the process environment instead of accepting it through a command-line option:
javascript
const apiKey = process.env.JUST_SERP_API_KEY;

if (!apiKey) {
  fail("Missing required JUST_SERP_API_KEY environment variable.");
}
  1. Use the environment-derived value only when constructing the request header:
javascript
const requestInit = {
  headers: {
    accept: "application/json",
    "X-API-Key": apiKey,
  },
  method: operation.method,
};
  1. Remove --api-key handling from parseArgs() and remove the flag from every documented invocation:
bash
JUST_SERP_API_KEY="..." node {baseDir}/bin/run.mjs \
  --operation "ScholarCiteSearch" \
  --params-json '{"query":"<query>"}'

Prefer setting the variable through a secret manager or protected execution environment rather than inline shell assignment, because inline assignments may also be retained in shell history or automation logs.

  1. Reject --api-key explicitly during migration so users do not unknowingly continue exposing credentials through process arguments.

  2. Review process-monitoring, CI/CD, and diagnostic systems for previously captured command lines. Rotate any key that may have been exposed.

  3. Ensure errors and debug output never include request headers, the environment-derived key, or the full argument vector.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes a network-capable helper (node ... run.mjs) and requires an API key, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where the runtime may permit broader external access than reviewers or users expect, reducing transparency and increasing the chance of unintended data egress or misuse of network access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description says the skill performs a query-driven Scholar Cite Search, while the operation definition indicates citation retrieval by an ID from a previous search result. In agentic systems, this semantic inconsistency is dangerous because tools may be selected and invoked under false assumptions, causing broken execution paths, incorrect chaining between skills, and potential disclosure of unintended identifiers or request data to a third-party API.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises a query-based Scholar Cite Search, but the required parameter is documented as a prior Google Scholar result ID. This mismatch can cause agents or users to supply the wrong kind of input, leading to failed requests, incorrect workflow chaining, or unintended data handling assumptions in downstream automation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The documentation only describes a language parameter for result retrieval and gives English as the example, but nowhere states that the user may choose the response language for the skill's own output. This can create an implicit language default without explicit user opt-in, which is a natural-language policy concern under locale/language choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.