Back to skill

Security audit

Google SERP Scholar Search API

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it handles the Just Serp API key in a way that can expose it through process command-line metadata.

Install only if you are comfortable sending Scholar search queries to Just Serp API and using your JUST_SERP_API_KEY with this helper. Prefer running it in a trusted local environment, avoid shared hosts or logged CI shells, and rotate the key if it may have appeared in process logs or monitoring telemetry.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:203
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis
"}' ``` ```text - Required: `JUST_SERP_API_KEY` - Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs. ``` ### Technical Analysis The helper requires the Just Serp API key to be supplied through the `--api-key` command-line argument. Shell expansion substitutes `$JUST_SERP_API_KEY` with its actual value before starting Node.js, placing the plaintext credential in the process argument vector. Depending on the operating system, container configuration, and ...[truncated 2147 chars]
Remediation
View remediation
"}' ``` 4. Where environment variables are unsuitable, accept the credential through protected standard input or a secret-manager integration rather than through command-line arguments. 5. Ensure diagnostic, error, and telemetry paths redact `X-API-Key`, `JUST_SERP_API_KEY`, and any legacy `--api-key` values. 6. Rotate any API key that may already have appeared in process telemetry, CI/CD logs, shell traces, or monitoring records. 7. Apply least-privilege service quotas and usage alerts to reduce the impact of future credential exposure. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes a network-capable helper (node .../run.mjs) and requires an API key, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch weakens policy enforcement and reviewability because an agent platform may permit outbound requests without a clearly declared network boundary, increasing the chance of unintended external data exfiltration or unauthorized API use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code builds an HTTP request to an external API using user-provided search parameters and an API key, then sends it with fetch. There is no confirmation prompt, user-facing log/print, or explanatory comment/docstring warning that query contents and credentials will be transmitted off-system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.