Back to skill

Security audit

Deer

Security checks for vulnerabilities and agentic risk

Overview

This clinic booking skill is mostly purpose-aligned, but it sends appointment details to external services without a clear confirmation step and ships unsafe API/URL-opening code that should be reviewed before use.

Install only if you are comfortable with booking details being sent to the BeautsGO/yestokr backend and with the current publisher fixing the confirmation, credential, URL-opening, and language-loading issues. Verify the clinic and platform identity before entering a phone number or appointment details.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
api/browser/open-url.js:18
Finding

Operating System Command Injection in URL-Opening Helper

Content
View full analysis
hostname === host || hostname.endsWith('.' + host)) } catch { return false } } async function openUrl(url) { if (!url) throw new Error('URL is required') if (!isAllowedUrl(url)) throw new Error(`URL not allowed: ${url}`) if (process.platform === 'darwin') { await execAsync(`open "${url}"`) } else if (process.platform === 'win32') { await execAsync(`start "" "${url}"`) } else { await execAsync(`xdg-open "${url}"`) } } ``` The file also exposes a command-line interface accepting the URL directly: ```javascript if (require.main === module) { openUrl(process.argv[2]) .then(() => { console.log(`✅ Opened: ${process.argv[2]}`); process.exit(0) }) .catch(err => { console.error(`❌ ${err.message}`); process.exit(1) }) } ``` ### Technical Analysis The helper validates the URL by parsing it with `new URL()`, but subsequently passes the original, unmodified URL into a shell command through `child_process.exec`. Enclosing the URL in double quotes does not make the command safe. On POSIX shells, command substitution constructs such as `$()` and backticks are evaluated inside double-quoted strings. Therefore, a URL can have an allowed HTTPS hostname while containing shell syntax in its path. The hostname allowlist only mitigates requests to unauthorized hosts; it does not sanitize the value for use as a shell argument. The helper is exported and is also directly executable from the command line, creating a concrete attacker-controlled input path. ### Attack Path 1. An attacker supplies a URL whose hostname is `i.beautsgo.com`, satisfying `isAll ...[truncated 1515 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
api/skill.js:21
Finding

Hardcoded API Credentials Exposed in Project Source

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
core/renderer.js:31
Finding

Path Traversal in Language Resource Loading

Content
View full analysis
/package.json ``` The `.json` suffix limits traversal to files with that extension, but it does not enforce the intended directory boundary. Moreover, `loadI18n` is exported directly and returns parsed file contents to its caller. Through the main rendering path, arbitrary JSON structures may not be rendered verbatim because the renderer expects specific translation keys. Nevertheless, the code performs unauthorized file access and parsing, can reveal file existence through differing errors, and can trigger failures by selecting malformed, large, or structurally unexpected JSON files. ### Attack Path 1. An attacker controls the `lang` input accepted by `processQuery`, or directly calls the exported `loadI18n` helper. 2. The attacker supplies traversal segments, such as: ```text ../package ``` 3. The constructed path resolves outside ...[truncated 1319 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
api/skill.js:164
Finding

Booking Data Is Transmitted Without an Explicit Confirmation Step

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a 鹿美人皮肤科 booking assistant, but the finding indicates the implementation may submit data to external APIs, open external URLs, provide app-download links, and possibly represent a different clinic/brand (JD皮肤科/BeautsGO). If true, this can mislead users about where their personal booking information is sent and which organization is actually handling it, creating a phishing/privacy-risk scenario.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a 鹿美人皮肤科 booking assistant, but the finding indicates the implementation may submit data to external APIs, open external URLs, provide app-download links, and possibly represent a different clinic/brand (JD皮肤科/BeautsGO). If true, this can mislead users about where their personal booking information is sent and which organization is actually handling it, creating a phishing/privacy-risk scenario.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is presented as a 鹿美人皮肤科 booking assistant, but the finding indicates the implementation may submit data to external APIs, open external URLs, provide app-download links, and possibly represent a different clinic/brand (JD皮肤科/BeautsGO). If true, this can mislead users about where their personal booking information is sent and which organization is actually handling it, creating a phishing/privacy-risk scenario.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill is presented as a 鹿美人皮肤科 booking assistant, but the finding indicates the implementation may submit data to external APIs, open external URLs, provide app-download links, and possibly represent a different clinic/brand (JD皮肤科/BeautsGO). If true, this can mislead users about where their personal booking information is sent and which organization is actually handling it, creating a phishing/privacy-risk scenario.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill is presented as a 鹿美人皮肤科 booking assistant, but the finding indicates the implementation may submit data to external APIs, open external URLs, provide app-download links, and possibly represent a different clinic/brand (JD皮肤科/BeautsGO). If true, this can mislead users about where their personal booking information is sent and which organization is actually handling it, creating a phishing/privacy-risk scenario.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
entry: api/skill.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
entry: api/skill.js

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description states that it can submit booking information to an API but provides no warning that personal data may be transmitted to an external service. In a medical/clinic context, appointment details may include sensitive personal or health-related information, so lack of transparency materially increases privacy and consent risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented booking flow says the skill will collect information and submit it to an appointment API without any explicit consent, privacy warning, or data-handling notice. Because this is a clinic-booking workflow, users may share names, contact details, and treatment interests, making silent transmission to external systems a meaningful privacy issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Contradictory stated intent between the manifest and source comments indicates the skill may have been repurposed or copied without fully updating its identity. In a healthcare booking context, this increases the risk of deceptive UX, incorrect routing, and unauthorized disclosure of user booking details to the wrong organization.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata describes one clinic while the implementation and in-code documentation target a different clinic. This mismatch can mislead users into sharing appointment details and contact information with an unintended provider or backend, which is a trust and privacy issue in a booking workflow handling personal data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api/skill.js (reported line 21)May include surrounding context.

js
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 17)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 30)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The main entry point sets lang = 'zh' by default, which forces a specific language/locale behavior. The file does not show any user choice, opt-in, or documented justification for restricting output to Chinese.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The booking flow transmits user contact information and appointment details to an external API, but the user-facing prompts do not clearly disclose that their data will be sent to a third-party service. Because the data includes phone numbers and medical-service appointment context, this creates a privacy and consent issue with potentially sensitive personal information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file's natural-language comments, function descriptions, and user-input examples are all Chinese-only, which can amount to a language policy violation when no user opt-in or locale scoping is stated. The allowed policy category explicitly covers skills that force a specific language without offering a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The render function defaults lang to zh, and the file’s comments and labels indicate a Chinese-first experience. This creates a language/locale constraint in natural-language behavior without an explicit user choice or opt-in, which matches the policy’s language/locale violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function defaults lang to 'zh', which imposes a specific language choice when the caller does not explicitly provide one. This is a natural-language locale policy concern because the skill does not offer or document user opt-in for that default within this file.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest file contains only a general description of the clinic and services, without any explicit trigger phrases, invocation conditions, or exclusions. In a manifest context, that can make activation scope ambiguous because the file does not clarify when the skill should be invoked versus ignored.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
api/skill.js:25