Back to skill

Security audit

Web Crawling Rendered Html API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a focused Just Serp web-crawling helper, but it needs review because arbitrary submitted URLs are sent to a third-party API and the API key is passed through command-line arguments.

Install only if you are comfortable sending target URLs to Just Serp API for remote crawling. Avoid private, internal, authenticated, or secret-bearing URLs, and prefer a version that reads the API key directly from a protected environment variable rather than passing it on the command line.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:40
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:40, SKILL.md:46, bin/run.mjs:67-69, and bin/run.mjs:84-88
Vulnerability Type: Credential exposure through process arguments
Risk Level: Medium

The documented invocation explicitly passes the Just Serp API key through the --api-key command-line argument:

bash
node {baseDir}/bin/run.mjs --operation "renderedHtml" --api-key "$JUST_SERP_API_KEY" --params-json '{"url":"<url>"}'

The accompanying instruction reinforces this usage:

markdown
- Pass the API key with `--api-key "$JUST_SERP_API_KEY"`; do not paste key values into chat messages, screenshots, or logs.

The executable requires the command-line value and places it in the outbound authentication header:

js
if (!args.apiKey) {
  fail("Missing required --api-key argument.");
}
js
const requestInit = {
  headers: {
    "accept": "application/json",
    "X-API-Key": args.apiKey,
  },
  method: operation.method,
};

Technical Analysis

Although the key is not deliberately printed by the script, passing it as a command-line argument places the expanded secret in the process argument vector. Depending on the operating-system configuration and execution environment, command lines may be accessible through process inspection utilities, process metadata interfaces, container management systems, audit services, crash diagnostics, shell tracing, or monitoring agents.

Environment-variable expansion does not prevent this exposure: the shell substitutes $JUST_SERP_API_KEY before starting Node.js, so the actual secret becomes part of the child process arguments. The code then parses and retains that value before transmitting it to the legitimate API endpoint as the X-API-Key header.

No hardcoded credential, deliberate credential exfiltration, persistence mechanism, or unauthorized destination was identified. The vulnerability is the insecure credenti ...[truncated 1355 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove --api-key from the documented command and read the credential directly from the environment:

    js
    const apiKey = process.env.JUST_SERP_API_KEY;
    
    if (!apiKey) {
      fail("Missing required JUST_SERP_API_KEY environment variable.");
    }
    
  2. Use the environment-derived value in the request header:

    js
    const requestInit = {
      headers: {
        "accept": "application/json",
        "X-API-Key": apiKey,
      },
      method: operation.method,
    };
    
  3. Update the documented invocation so the key is not supplied as an argument:

    bash
    JUST_SERP_API_KEY="$JUST_SERP_API_KEY" node {baseDir}/bin/run.mjs \
      --operation "renderedHtml" \
      --params-json '{"url":"<url>"}'
    

    If the variable is already exported, omit the assignment entirely.

  4. Remove support for the --api-key flag to prevent users from accidentally reverting to the insecure mechanism. If backward compatibility is temporarily required, emit a deprecation warning without including the supplied value.

  5. Ensure application logs, shell tracing, process-monitoring agents, CI job output, and diagnostic tooling do not capture secrets. Prefer an operating-system or orchestration-platform secret manager for production deployments.

  6. Rotate any API keys previously used through the documented command where untrusted users or telemetry systems may have had access to process metadata.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill performs network-accessing behavior via a helper that calls an external API, but it does not declare any explicit tool scope such as allowed-tools or permissions. This weakens review and containment because downstream systems or users cannot clearly see or enforce that the skill can make outbound requests, increasing the risk of unintended data egress or misuse of user-supplied URLs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script requires an --api-key argument and places it in the X-API-Key request header, which is a sensitive credential operation. There is no visible warning, prompt, or explanatory comment/docstring informing users that they are providing a secret that will be sent to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill forwards a user-supplied target URL to a third-party crawling service, which means user-provided destinations and potentially sensitive internal or private URLs are disclosed off-platform. In this context, the capability is the core purpose of the skill, but the code provides no warning, restriction, or validation to prevent crawling localhost, RFC1918/private hosts, or otherwise sensitive resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This skill sends a user-supplied target URL to a third-party crawling service, but the manifest text does not clearly disclose that user-provided URLs and associated browsing targets will be transmitted off-platform. That creates a privacy and trust issue because users may assume the crawl happens locally or within the host product, and may unknowingly submit sensitive internal, private, or tokenized URLs to an external provider.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file documents a capability to crawl a user-supplied URL and return full raw rendered HTML, which can include personal, sensitive, or copyrighted page content. Under the markdown-specific warning criteria, the description should disclose that fetching and returning page contents may affect privacy or data handling expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.