Back to skill

Security audit

Web Crawling Markdown API

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate Just Serp web-to-Markdown wrapper, but it needs Review because it sends submitted URLs to a third-party crawler and handles the API key through command-line arguments.

Install only if you are comfortable sending target URLs to Just Serp API. Avoid using it with private, internal, authenticated, or sensitive links, and prefer a version that reads JUST_SERP_API_KEY directly from the environment instead of passing the secret as a command-line argument.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/run.mjs:76
Finding

API Key Exposed Through Process Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:38, SKILL.md:44, bin/run.mjs:76-78, bin/run.mjs:87-90
Vulnerability Type: API credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

SKILL.md:38:

bash
node {baseDir}/bin/run.mjs --operation "markdown" --api-key "$JUST_SERP_API_KEY" --params-json '{"url":"<url>"}'

SKILL.md:44:

markdown
- Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs.

bin/run.mjs:76-78:

js
if (!args.apiKey) {
  fail("Missing required --api-key argument.");
}

bin/run.mjs:87-90:

js
const requestInit = {
  headers: {
    "accept": "application/json",
    "X-API-Key": args.apiKey,

Technical Analysis

The documented execution method expands JUST_SERP_API_KEY into the value of the --api-key command-line argument. The script then consumes that argument and places it in the X-API-Key request header.

Environment-variable expansion occurs in the invoking shell before Node.js starts. Consequently, the expanded credential becomes part of the process argument vector. Depending on operating-system permissions and deployment configuration, process arguments may be visible through process inspection interfaces, administrative utilities, monitoring agents, crash diagnostics, audit systems, or orchestration telemetry.

The credential is transmitted to the declared API service over HTTPS, and no evidence shows that the script deliberately logs it. The weakness is specifically the unnecessary placement of the secret in process arguments.

Attack Path

  1. A victim follows the documented command and invokes the helper with --api-key "$JUST_SERP_API_KEY".
  2. The shell expands JUST_SERP_API_KEY, placing the plaintext credential in the Node.js process argument vector.
  3. While the process is running—or through previo ...[truncated 867 chars]
Remediation
View remediation

Remediation Suggestions

  1. Read the credential directly from the environment rather than accepting it through a command-line argument:

    js
    const apiKey = process.env.JUST_SERP_API_KEY;
    
    if (!apiKey) {
      fail("Missing required JUST_SERP_API_KEY environment variable.");
    }
    
  2. Use the environment-derived value when constructing the request:

    js
    const requestInit = {
      headers: {
        "accept": "application/json",
        "X-API-Key": apiKey,
      },
      method: operation.method,
    };
    
  3. Remove --api-key parsing from parseArgs and reject command-line credential input to prevent accidental exposure.

  4. Update the documented invocation to avoid expanding the key into argv:

    bash
    JUST_SERP_API_KEY="$JUST_SERP_API_KEY" node {baseDir}/bin/run.mjs \
      --operation "markdown" \
      --params-json '{"url":"https://www.example.com"}'
    
  5. If environment-based secret injection is unsuitable, accept the credential through a protected file descriptor or a file with restrictive permissions rather than through argv.

  6. Ensure monitoring, crash reporting, and audit systems redact API keys and command-line secret flags. Rotate any key suspected of having been captured in process telemetry.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes a network-capable helper (node {baseDir}/bin/run.mjs) that performs outbound requests to a third-party API, but the manifest does not declare an explicit tool scope such as permissions or allowed-tools. This creates a policy gap: an agent or reviewer cannot easily enforce or audit the skill's network access, increasing the risk of unintended external requests, data exfiltration, or SSRF-style abuse if user-controlled URLs are passed through unchecked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest explicitly sends a user-supplied URL to an external crawling provider but provides no warning that the URL and associated request metadata will be disclosed to a third party. This creates privacy and operational risk because users may submit confidential links, internal endpoints, or tracking-bearing URLs without understanding that they are being transmitted off-platform.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill exposes a broadly described web-crawling capability with no documented restrictions on what URLs may be fetched or when the action should be used. In an agent context, this can enable unsafe retrieval of arbitrary user-provided or model-selected URLs, increasing the risk of unintended external requests, access to sensitive endpoints, or use in prompt-injection delivery chains.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.