Back to skill

Security audit

A transparent proxy for the Facebook Graph API. Replace the domain, pass your Yuri API token, and call any Facebook endpoint — no Facebook access token needed on the client side.

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed third-party Facebook API proxy, but it needs review because it routes powerful Facebook actions through the provider and teaches URL-based token use.

Use this only with least-privilege test or sandbox Facebook resources unless you have verified the provider's authorization isolation, token storage, log redaction, and deletion controls. Avoid production or long-lived tokens, prefer body/header-based secret handling where available, and rotate or revoke the Yuri token immediately if it is ever used in a copied URL, shell history, browser history, or logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:109
Finding

Sensitive API Token Exposed Through URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 109–115
Vulnerability Type: Sensitive credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code Snippet

bash
curl "https://facebook-graph.baiz.ai/v21.0/act_123456/campaigns?fields=name,status&access_token=yuri_sk_XXXXX"

Technical Analysis

The primary usage example instructs users to supply the sensitive YURI_TOKEN in the URL query string. Although the displayed value is a placeholder rather than a live secret, users following the example will replace it with a real credential.

Query-string credentials can be recorded in shell history, browser history, HTTP access logs, reverse-proxy and CDN logs, monitoring systems, error reports, and other telemetry. HTTPS encrypts the URL while it is in transit, but it does not prevent either endpoint or authorized intermediaries from recording the complete request target.

The document itself acknowledges this exposure risk in SKILL.md, lines 148–150:

text
Because the token is passed as a query parameter, it may appear in browser history, server access logs, proxy logs, and CDN logs. For POST/PUT requests, prefer passing the token in the request body (as a form field `access_token`) instead of the URL query string.

The warning reduces but does not eliminate the vulnerability because the primary copyable example still demonstrates unsafe handling, and body-based transport is not generally suitable for GET requests. No header-based authentication mechanism is documented.

Attack Path

  1. A user copies the documented command and replaces yuri_sk_XXXXX with an active Yuri token.
  2. The command containing the token is retained in shell history, or the complete request URL is captured by gateway, proxy, CDN, observability, or diagnostic logs.
  3. An attacker or unauthorized operator with access to one of those records extracts the token.
  4. The attacker sub ...[truncated 897 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add support for sending the Yuri token in an Authorization header and make that mechanism the default in every example.
  2. If query-string authentication must remain for compatibility, clearly label it as a legacy or last-resort mechanism rather than presenting it as the primary quick-start pattern.
  3. Provide copyable examples that avoid placing literal credentials in command arguments. Read the token from a protected environment variable or secret manager while accounting for command-line and process-inspection risks.
  4. Configure the gateway, load balancers, reverse proxies, CDNs, application monitoring, and error-reporting systems to redact access_token values before storage or transmission.
  5. Avoid logging complete query strings. Where request targets must be logged, use an explicit parameter allowlist and replace credential values with a fixed redaction marker.
  6. Use short-lived, least-privilege, narrowly scoped tokens and provide automated rotation and immediate revocation controls.
  7. Add secret-detection monitoring for operational logs and establish an incident procedure that revokes any token found in a URL or log.
  8. Update the quick-start documentation to demonstrate the secure authentication method first and explain that TLS alone does not prevent credential retention at endpoints.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
primary_credential: YURI_TOKEN
env:
  YURI_TOKEN:
    description: "API Token from baiz.ai platform. Generate it in the Yuri dashboard under 'API Management'. Format: yuri_sk_XXXXX. This is NOT a Facebook access token — it replaces the access_token parameter in API calls. Use a least-privilege test account token."
    required: true
    sensitive: true
---

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This section instructs users to pass a sensitive platform credential as the access_token parameter, encouraging transmission of the token in locations commonly captured by logs, histories, and intermediaries. Even though the document acknowledges this risk, normalizing token-in-parameter handling increases the chance of credential leakage and downstream account compromise through the proxy.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
### Token Handling / Token 说明

- **Token format / Token 格式**
  The Yuri token (format `yuri_sk_XXXXX`) is a Yuri platform credential, **not** a Facebook access token. It is passed as the `access_token` query parameter — no special headers needed.
  尤里改 Token(格式 `yuri_sk_XXXXX`)是尤里改平台凭证,**不是** Facebook Access Token。作为 `access_token` 查询参数传入即可。

- **Server-side injection / 服务端注入**

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The skill states that Facebook access tokens are stored and managed on the server and that the gateway injects the correct token based on the resource ID in the request path. This describes a credential mediation service with broad server-side access to third-party tokens; if the mapping or authorization checks are flawed, users could access another team's Facebook resources or expose centrally stored credentials.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
- **Token format / Token 格式**
  The Yuri token (format `yuri_sk_XXXXX`) is a Yuri platform credential, **not** a Facebook access token. It is passed as the `access_token` query parameter — no special headers needed.
  尤里改 Token(格式 `yuri_sk_XXXXX`)是尤里改平台凭证,**不是** Facebook Access Token。作为 `access_token` 查询参数传入即可。

- **Server-side injection / 服务端注入**
  Facebook access tokens are securely stored and managed on the server. The gateway resolves the correct token based on the resource ID in your request path — tokens are never exposed to the client.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This text again describes server-side handling of Facebook access tokens and automatic token selection from request-path resource IDs. That pattern is security-sensitive because path-derived token resolution can enable confused-deputy or insecure direct object reference style failures if an attacker can reference unauthorized resource IDs.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
尤里改 Token(格式 `yuri_sk_XXXXX`)是尤里改平台凭证,**不是** Facebook Access Token。作为 `access_token` 查询参数传入即可。

- **Server-side injection / 服务端注入**
  Facebook access tokens are securely stored and managed on the server. The gateway resolves the correct token based on the resource ID in your request path — tokens are never exposed to the client.
  Facebook Access Token 由服务端安全托管,网关根据请求路径中的资源 ID 自动匹配注入,不会暴露给客户端。

- **Token in URL risk / Token 在 URL 中的风险**

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This section explicitly states that the token is passed as a query parameter and only suggests request-body placement for some methods. Secrets in URLs are routinely exposed through browser history, reverse proxies, analytics systems, referer leakage, and server/CDN logs, making credential compromise substantially more likely.

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
- **Server-side injection / 服务端注入**
  Facebook access tokens are securely stored and managed on the server. The gateway resolves the correct token based on the resource ID in your request path — tokens are never exposed to the client.
  Facebook Access Token 由服务端安全托管,网关根据请求路径中的资源 ID 自动匹配注入,不会暴露给客户端。

- **Token in URL risk / Token 在 URL 中的风险**
  Because the token is passed as a query parameter, it may appear in browser history, server access logs, proxy logs, and CDN logs. For POST/PUT requests, prefer passing the token in the request body (as a form field `access_token`) instead of the URL query string.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
每个尤里改 Token 仅限创建它的团队使用。可随时在后台重新生成或吊销,建议优先使用短期 Token 并频繁轮换(如 30–90 天)。

- **Facebook token lifecycle / Facebook Token 生命周期**
  The gateway uses short-lived Facebook access tokens where possible and automatically refreshes them. Long-lived tokens are encrypted at rest with AES-256 and scoped per-team.
  网关尽可能使用短期 Facebook Access Token 并自动续期;长期 Token 使用 AES-256 加密存储,按团队隔离。

### Data & Logging / 数据与日志

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
- **Facebook token lifecycle / Facebook Token 生命周期**
  The gateway uses short-lived Facebook access tokens where possible and automatically refreshes them. Long-lived tokens are encrypted at rest with AES-256 and scoped per-team.
  网关尽可能使用短期 Facebook Access Token 并自动续期;长期 Token 使用 AES-256 加密存储,按团队隔离。

### Data & Logging / 数据与日志

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The logging policy says request metadata including URL path is retained, while the skill elsewhere instructs users to pass the token as the access_token parameter. If query strings are included in logged URLs or adjacent logging systems capture full request URIs, sensitive credentials may be retained for 90 days or longer, expanding blast radius after any log exposure.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
| Item | Policy |
|------|--------|
| **Request logging**<br>请求日志 | Proxied request metadata (URL path, HTTP method, status code, timestamp) is logged for billing and troubleshooting. Request and response bodies are **not** persisted.<br>代理请求元数据会被记录用于计费与排障,请求体和响应体**不会**持久化。 |
| **Encrypted storage**<br>加密存储 | All Facebook access tokens are encrypted at rest using AES-256, scoped by team-level permissions.<br>所有 Facebook Access Token 使用 AES-256 加密存储,按团队级别权限隔离。 |
| **Data retention**<br>日志保留 | Request metadata: 90 days, then auto-purged. Billing records: 1 year (financial compliance). Users can request early deletion.<br>请求元数据保留 90 天后自动清除。计费记录保留 1 年。可联系客服申请提前删除。 |
| **Audit logs**<br>审计日志 | Token creation, revocation, and Facebook account binding events are logged in the Yuri dashboard under **Audit Log**, visible to team admins.<br>Token 操作和账号绑定事件均记录在后台「审计日志」中,团队管理员可查看。 |

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The logging policy says request metadata including URL path is retained, while the skill elsewhere instructs users to pass the token as the access_token parameter. If query strings are included in logged URLs or adjacent logging systems capture full request URIs, sensitive credentials may be retained for 90 days or longer, expanding blast radius after any log exposure.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
| Item | Policy |
|------|--------|
| **Request logging**<br>请求日志 | Proxied request metadata (URL path, HTTP method, status code, timestamp) is logged for billing and troubleshooting. Request and response bodies are **not** persisted.<br>代理请求元数据会被记录用于计费与排障,请求体和响应体**不会**持久化。 |
| **Encrypted storage**<br>加密存储 | All Facebook access tokens are encrypted at rest using AES-256, scoped by team-level permissions.<br>所有 Facebook Access Token 使用 AES-256 加密存储,按团队级别权限隔离。 |
| **Data retention**<br>日志保留 | Request metadata: 90 days, then auto-purged. Billing records: 1 year (financial compliance). Users can request early deletion.<br>请求元数据保留 90 天后自动清除。计费记录保留 1 年。可联系客服申请提前删除。 |
| **Audit logs**<br>审计日志 | Token creation, revocation, and Facebook account binding events are logged in the Yuri dashboard under **Audit Log**, visible to team admins.<br>Token 操作和账号绑定事件均记录在后台「审计日志」中,团队管理员可查看。 |

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file embeds parallel Chinese-language instructions alongside English, but does not state whether bilingual output is optional, user-selected, or required by policy. Under the stated rule, forcing or assuming a specific language/locale without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.