Back to skill

Security audit

Google SERP Shorts Search API

Security checks for vulnerabilities and agentic risk

Overview

This is a narrow Just Serp API wrapper, but it should be reviewed because it passes the API key on the command line where local process logs or monitoring could expose it.

Review before installing if your Just Serp API key is billable, shared, or used in monitored environments. Prefer a version that reads JUST_SERP_API_KEY directly from the environment instead of passing it with --api-key, and rotate the key if it may already have appeared in process logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:52
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis
"}' ``` The environment instructions explicitly require this invocation pattern: ```markdown - Required: `JUST_SERP_API_KEY` - Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs. ``` The helper requires the command-line API key and subsequently places it in the request header: ```javascript if (!args.apiKey) { fail("Missing required --api-key argument."); } const params = parseParams(args.paramsJson); applyDefaults(operation, params); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url); const requestInit = { headers: { "accept": "application/json", "X-API-Key": args.apiKey, }, method: operation.method, }; ``` ### Technical Analysis Shell expansion of `"$JUST_SERP_API_KEY"` occurs before Node.js starts. The resulting plaintext credential is placed in the process argument vector as the value of `--api-key`. Depending on operating-system access controls and deployment configuration, command-line arguments may be visible through process inspection utilities, process metadata interfaces, monitoring agents, diagnostic tools, crash collectors, audit systems, or command execution logs. This creates a credential-disclosure channel even though the key is not printed by the application itself. The implementation also requires `args.apiKey`, making the insecure command-line mechanism the expected authen ...[truncated 1910 chars]
Remediation
View remediation
"}' ``` If the variable is already exported, it does not need to appear in the invocation: ```bash node {baseDir}/bin/run.mjs \ --operation "shortsSearch" \ --params-json '{"query":""}' ``` 4. If explicit credential injection is necessary, accept it through protected standard input, a permission-restricted file descriptor, or a platform secret manager rather than through command-line arguments. 5. Ensure error handling, debug output, telemetry, and request logging redact the `X-API-Key` header and the `JUST_SERP_API_KEY` value. 6. Deprecate and reject `--api-key` to prevent users from continuing to expose credentials through legacy invocation patterns. 7. Rotate any API key previously used through this command if process arguments may have been captured by shared-host users, monitoring systems, or execution logs. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) and is explicitly designed to call a remote API, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens policy enforcement and reviewability because the runtime may permit outbound requests without a clearly declared boundary, increasing the chance of unintended or over-broad network access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The documentation presents language and lr as direct controls for forcing result language and language restriction, but it does not state that language or locale should be chosen by the user. Because language/locale policy violations apply to all file types, this can be read as encouraging locale-specific behavior without explicit opt-in or a documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.