T09 · Insecure Skill Coding Practices
- Location
SKILL.md:36- Finding
API Credential Exposed in MCP Endpoint Query Parameters
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Exa web-search MCP integration, but its setup encourages API keys in URLs and its people-search examples lack privacy guardrails.
Review before installing. Use the unauthenticated MCP URL where possible, avoid storing an Exa API key directly in a shared URL or config, rotate any key that has been exposed in logs or screenshots, and use people/profile search only for legitimate, authorized public research with appropriate privacy and platform-term checks.
SKILL.md:36API Credential Exposed in MCP Endpoint Query Parameters
The skill instructs users to place the Exa API key directly in the MCP server URL query string. Secrets embedded in URLs are commonly exposed through config files, logs, process listings, browser/history artifacts, telemetry, screenshots, and shared error reports, creating an avoidable credential leakage risk.
The skill explicitly promotes people/profile search and LinkedIn-style discovery, and also encourages extracting content from known URLs, including profile URLs, without any privacy, consent, or acceptable-use guidance. In an agent context this increases the chance of collecting, aggregating, or enriching personal data in ways that may violate privacy expectations, platform terms, or internal policy.
No suspicious patterns detected.