Back to skill

Security audit

Barog

Security checks for vulnerabilities and agentic risk

Overview

This Barog booking skill is mostly coherent, but it needs review because it can submit appointment/contact data without the promised confirmation and includes an unsafe browser-opening helper.

Before installing, understand that this skill can open BeautsGO pages and submit booking details, including phone number if provided, to external booking services. It should add a clear confirmation step before submission, remove shell-based URL opening, and move API credentials out of the distributed package.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
api/browser/open-url.js:18
Finding

Shell Command Injection in the URL-Opening Utility

Content
View full analysis
hostname === host || hostname.endsWith('.' + host)) } catch { return false } } async function openUrl(url) { if (!url) throw new Error('URL is required') if (!isAllowedUrl(url)) throw new Error(`URL not allowed: ${url}`) if (process.platform === 'darwin') { await execAsync(`open "${url}"`) } else if (process.platform === 'win32') { await execAsync(`start "" "${url}"`) } else { await execAsync(`xdg-open "${url}"`) } } ``` ### Technical Analysis The function validates the parsed URL protocol and hostname, but it subsequently interpolates the original, untrusted URL string into an operating-system shell command executed through `child_process.exec`. Hostname validation does not make the complete URL safe for shell interpolation. On Unix-like systems, command substitutions such as `$()` and backticks are still evaluated inside double quotes. Consequently, a URL can have an allowed `i.beautsgo.com` hostname while containing shell metacharacters in its path, query, or fragment. For example, a conceptual input with an allowed hostname and a path containing `$(attacker-command)` would pass `isAllowedUrl()`. When embedded in the `xdg-open` or `open` command, the shell could evaluate the substitution before launching the browser. The normal `processQuery` routes currently derive URLs from bundled hospital data, which limits exposure through the primary Skill interface. However, `openUrl` is exported, and `api/browser/open-url.js:41-44` also exposes it directly through the command line. The vulnerable function therefore remains independently reachable if anot ...[truncated 1359 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
api/skill.js:21
Finding

API Credentials Embedded in Distributable Source Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
api/skill.js:164
Finding

Booking Data Is Transmitted Without the Declared Explicit Consent Step

Content
View full analysis
信息不全也没关系,分多次告诉我也可以 😊` } ``` Once a date is present, the code constructs and immediately submits the payload without a separate confirmation: ```js const dateISO = parseDateToISO(formData.dateText) const expectedTime = formData.timeSlot && formData.timeSlot !== '全天' ? `${dateISO} ${formData.timeSlot}` : `${dateISO} 全天` const payload = { contact: formData.contact || '', expected_time: expectedTime, project_type: '', d_id: '', h_id: hospital.id, p_id: '', num: formData.persons, source_type: 'skill', } const result = await submitBookingApi(payload) ``` ### Technical Analysis The manifest states that a user-provided phone number is sent only after explicit agreement and when the user initiates booking and provides contact information. The runtime does not implement a distinct consent or final-confirmation state. Instead, recognizing a booking intent and a date is sufficient to trigger a network submission. The transmitted payload also contains more information than the manifest's `data_colle ...[truncated 1947 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the underlying code or assets actually target a different clinic identity than the declared Barog hospital skill, that is a genuine trust and integrity problem: users may disclose personal booking information under the wrong brand or be redirected to an unintended service. In a medical-booking context, identity confusion is more dangerous because it can misroute sensitive personal and health-adjacent data and undermine informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the underlying code or assets actually target a different clinic identity than the declared Barog hospital skill, that is a genuine trust and integrity problem: users may disclose personal booking information under the wrong brand or be redirected to an unintended service. In a medical-booking context, identity confusion is more dangerous because it can misroute sensitive personal and health-adjacent data and undermine informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the underlying code or assets actually target a different clinic identity than the declared Barog hospital skill, that is a genuine trust and integrity problem: users may disclose personal booking information under the wrong brand or be redirected to an unintended service. In a medical-booking context, identity confusion is more dangerous because it can misroute sensitive personal and health-adjacent data and undermine informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the underlying code or assets actually target a different clinic identity than the declared Barog hospital skill, that is a genuine trust and integrity problem: users may disclose personal booking information under the wrong brand or be redirected to an unintended service. In a medical-booking context, identity confusion is more dangerous because it can misroute sensitive personal and health-adjacent data and undermine informed consent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
entry: api/skill.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
entry: api/skill.js

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata describes Barog医院, but the code comments identify it as a JD皮肤科预约技能 and indicate it may have been repurposed from another clinic. In a booking skill that collects contact details and submits appointments to external APIs, identity confusion can mislead users about which clinic will receive their information or booking request, creating privacy, consent, and misrouting risks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The header comment explicitly says this is a JD clinic booking skill while the manifest says Barog clinic. Although this is documentation-level evidence, in this context it is a meaningful trust and maintenance issue because operators may ship the wrong configuration or fail to notice that user data is being handled for a different tenant than intended.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api/skill.js (reported line 21)May include surrounding context.

js
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 17)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 30)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The main handler hard-codes Chinese as the default language, which can force a specific locale on users who have not opted in. Under the policy, locale constraints should either be user-selectable or clearly justified as region-specific; this file does not provide such an opt-in mechanism.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill transmits user-provided contact information and appointment details to a third-party booking API as soon as sufficient form data is parsed, without a clear just-in-time disclosure or explicit consent step. This is dangerous because users may not realize their phone number and scheduling data are leaving the assistant and being processed by an external service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file header and logic describe a JD皮肤科预约技能 while the manifest identifies the skill as Barog医院(江南店). In a medical booking workflow, clinic identity confusion can misroute users, prices, or appointments and undermine consent because users may believe they are interacting with a different provider than the one actually configured.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Natural-language handling throughout the file is hard-coded around Chinese phrases and Chinese date/time expressions, while the skill description is also Chinese-specific. There is no indication that users can opt into another language or that this locale restriction is explicitly documented as a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code parses and captures a mobile phone number from free-form user input, but this file shows no accompanying notice, consent step, minimization, or handling constraints for that personal data. In a medical appointment context, collecting contact information without clear disclosure increases privacy and compliance risk, especially if users are not told why it is needed or how it will be used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The render function defaults lang to 'zh', which forces Chinese output whenever the caller does not explicitly choose a language. Under the policy, locale or language must not be imposed without user choice unless clearly documented and justified, which is not present in this file.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The string "Please tell me what you need — I'll help you..." is a very general assistance phrase that could match many unrelated user requests. In a manifest/localization context, this creates an ambiguous trigger or routing cue without clear scope limitations or exclusion conditions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The inline example for price extraction explicitly references JD皮肤科, which contradicts the Barog clinic identity in the skill metadata. Although this is only documentation, such mismatches in a healthcare booking skill can propagate into prompts, tests, or downstream behavior and cause users to receive information for the wrong clinic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function defaults lang to 'zh', which imposes a specific locale when the caller does not explicitly choose one. This is a natural-language policy concern because it biases output language without documented user opt-in or justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest presents the skill name and description entirely in Chinese, which can impose a specific language on users without indicating any opt-in or locale selection. Under the policy for natural-language violations, forcing a language without user choice can be a compliance issue unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest sets the input language default to "zh", which can force a specific language/locale for users who do not explicitly choose one. The policy allows locale constraints when users are given a choice or the constraint is clearly justified, but this default applies automatically without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
api/skill.js:25