Back to skill

Security audit

Dana

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches a clinic booking assistant, but it has unsafe browser-opening code and submits appointment details externally without a clear separate confirmation step.

Review before installing. The skill is not clearly malicious, but users should know that booking details may be sent to an external appointment API as soon as a booking request with a date is parsed, and maintainers should replace shell-based URL opening, remove or rotate bundled API tokens, add an explicit confirmation step, and provide integrity guidance for the APK link.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
api/browser/open-url.js:29
Finding

Shell Command Injection in URL Opener

Content
View full analysis
Remediation
View remediation
{ const child = spawn(executable, args, { shell: false, stdio: 'ignore' }) child.once('error', reject) child.once('exit', code => { if (code === 0) resolve() else reject(new Error(`Browser opener exited with code ${code}`)) }) }) } async function openUrl(url) { if (!url) throw new Error('URL is required') if (!isAllowedUrl(url)) throw new Error('URL not allowed') if (process.platform === 'darwin') { await run('open', [url]) } else if (process.platform === 'win32') { await run('cmd.exe', ['/d', '/s', '/c', 'start', '', url]) } else { await run('xdg-open', [url]) } } ``` On Windows, avoid `cmd.exe` where possible because it introduces another command parser. Prefer a shell-free platform API or a well-reviewed browser-opening library. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
api/skill.js:19
Finding

Hardcoded API Credentials Distributed in Source Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
api/skill.js:172
Finding

Appointment Data Is Transmitted Without a Distinct Confirmation Step

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
api/skill.js:231
Finding

Direct APK Distribution Without Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill is about a specific skin clinic and its aesthetic treatment offerings. However, the supplied code does not provide clinic information, dermatology features, booking logic, or treatment-related behavior. Its sole function is to validate a URL against a BeautsGO whitelist and launch it in the user's default browser using OS commands. That is a materially different primary purpose and an undeclared capability, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述强调的是某家首尔皮肤科及其提供的医美项目,像是医院简介/服务展示;但代码的核心功能是交互式预约与导流工具,包含意图识别、收集预约日期/人数/联系方式、向外部接口提交预约、查询价格、打开客服和下载 APP。虽然这些能力与医美场景相关,但它们属于重要的可执行能力,声明中未体现。另一个明显问题是代码注释写的是“JD皮肤科预约技能”,与声明中的“明洞丹雅皮肤科”不一致,说明对象也可能不匹配。因此描述不能准确代表代码实际行为。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

该代码不仅用于展示或介绍皮肤科项目,还明确实现了预约、咨询、价格查询、打开页面和下载等交互能力,其中预约表单解析会提取人数、日期、时间段和手机号。这些属于更具体的事务处理与用户数据处理能力,明显超出“提供皮肤管理、激光、注射等医美项目”的静态描述。更重要的是,代码注释直接写明为“JD皮肤科预约技能”,与声明中的“明洞丹雅皮肤科”不一致,说明描述与实际服务对象/用途存在实质偏差。因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description says this skill is about a specific dermatology clinic and its offered aesthetic medical services. However, the provided code does not implement clinic service information, search, or presentation of treatments. Instead, it is a rendering layer for appointment content: it reads localization files from disk, merges hospital data into templates, produces Markdown booking guidance, and performs text cleanup. This indicates a materially different primary purpose—booking/appointment output generation rather than representing the clinic's medical-service description. The filesystem access for loading i18n resources is also undeclared, though it may be a supporting detail; the main mismatch is the skill purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
entry: api/skill.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
entry: api/skill.js

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file header says this is a "JD皮肤科预约技能" entrypoint, but the manifest names the skill as dana-booking for 明洞丹雅皮肤科. The runtime behavior uses hospital data from an external JSON and returns hospital-specific booking, pricing, and consultation flows, so this comment actively misstates which clinic the skill is for.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api/skill.js (reported line 21)May include surrounding context.

js
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 17)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 30)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The main entry point sets lang = 'zh' by default, and the surrounding user-facing strings are all Chinese. This imposes a specific language/locale on users without an explicit choice or documented justification, which matches the language policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The booking flow transmits personal data including contact information, appointment date/time, and party size to an external API endpoint without clearly informing the user before submission or obtaining explicit consent. In a healthcare/medical-aesthetics context, this is more sensitive than ordinary scheduling data and creates privacy, compliance, and trust risks if users do not realize their information is leaving the assistant environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The render function hard-codes lang = 'zh' as the default, which makes Chinese the enforced output language when no explicit user choice is provided. This is a natural-language locale policy concern because the file does not indicate an opt-in mechanism or user-selectable fallback at the point of use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The title and description force a specific language presentation, but the manifest does not state that the skill is intended only for Chinese-speaking users or provide any language choice. This can violate language/locale policy expectations when users have not opted into that language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains user-facing natural-language comments and usage text entirely in Chinese, such as the file description and usage instructions. Under the language/locale policy rule, forcing a specific language without opt-in can be a policy violation when no alternative language choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

文件中的自然语言说明、示例输入输出以及意图规则均默认并限定为中文场景,没有提供语言选择或说明该技能仅面向中文用户。按照语言/locale 政策,若技能强制特定语言而无用户选择或明确限定,可能构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

该代码会从自然语言输入中提取手机号并保存到 result.contact,这属于处理用户敏感联系方式的行为。文件中的注释仅描述功能实现,没有任何面向用户的提示、确认或隐私披露,容易让用户在未被明确告知的情况下提交个人信息。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The getBookingGuide function sets lang = 'zh' as the default, which imposes a specific language choice when the caller does not explicitly opt in. The policy forbids forcing a language or locale unless the skill offers a choice or clearly documents and justifies the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The JSON includes locale-specific /cn/ URLs and primarily Chinese naming fields for user-facing access, but provides no indication that the user can opt into another language or locale. This can violate the language/locale policy when a skill forces a specific locale experience without documented choice or justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
api/skill.js:25