Back to skill

Security audit

Jeju With

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches a BeautsGO hospital-booking assistant, but it can send appointment details without a separate confirmation and includes an unsafe browser-opening helper.

Review before installing. Use only if you are comfortable with BeautsGO receiving the selected hospital, appointment date/time, party size, source metadata, and any phone number you provide; the publisher should add a final confirmation prompt, document all transmitted fields, move API tokens out of distributed source, and replace shell-based URL opening with an argument-safe launcher.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
api/browser/open-url.js:29
Finding

Shell Command Injection in the URL Opener

Content
View full analysis
{ console.log(`✅ Opened: ${process.argv[2]}`); process.exit(0) }) .catch(err => { console.error(`❌ ${err.message}`); process.exit(1) }) } module.exports = { openUrl } ``` ### Technical Analysis The URL is interpolated into a command string passed to `child_process.exec`. Unlike argument-based process APIs, `exec` invokes an operating-system shell. A URL containing quotation marks and shell metacharacters can terminate the intended quoted argument and append another shell command. The `isAllowedUrl` check verifies that the protocol is HTTPS and that the parsed hostname belongs to `i.beautsgo.com`. That validation prevents arbitrary destinations, but it does not make the complete URL safe for shell interpretation. Shell metacharacters can occur outside the parsed hostname, such as in the path, query string, or fragment. Current calls from `api/skill.js` use static hospital URLs, which limits exposure through the normal intent flow. However, `openUrl` is exported for other callers, and the module directly accepts `process.argv[2]` when run as a command-line program. ### Attack Path 1. An attacker obtains control over a URL supplied to the exported `openUrl` function or the script's first command-line argument. 2. The attacker supplies an HTTPS URL whose hostname passes the `i.beautsgo.com` allowlist. 3. Th ...[truncated 817 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
api/skill.js:21
Finding

API Authentication Tokens Hard-Coded in Source Code

Content
View full analysis
Remediation
View remediation

other

Warning
Location
api/skill.js:160
Finding

Appointment Data Is Transmitted Without the Declared Explicit Consent Step

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented purpose suggests a hospital information/booking assistant, but the behavior expands into submitting appointment data to external APIs, opening pricing/chat/detail pages, and promoting BeautsGO app downloads tied to a narrower beauty-booking workflow. In a medical context, this mismatch is more dangerous because users may disclose sensitive health-related and personal information without understanding that third-party services, not just the named hospital, are involved.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose suggests a hospital information/booking assistant, but the behavior expands into submitting appointment data to external APIs, opening pricing/chat/detail pages, and promoting BeautsGO app downloads tied to a narrower beauty-booking workflow. In a medical context, this mismatch is more dangerous because users may disclose sensitive health-related and personal information without understanding that third-party services, not just the named hospital, are involved.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
entry: api/skill.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
entry: api/skill.js

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api/skill.js (reported line 21)May include surrounding context.

js
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 17)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 30)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This natural-language behavior hardcodes a Chinese default for responses, which can amount to forcing a specific language without user opt-in. The file does not show any user-facing mechanism to choose another language or explain that the skill is intentionally restricted to Chinese users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The booking flow transmits personal data including contact information, appointment date/time, and party size to an external API without any explicit pre-submission notice or consent checkpoint in the user-facing flow. In a medical-booking context, this is more sensitive than ordinary commerce because the destination hospital and booking details can reveal health-related interests or treatment intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The render function defaults to lang = 'zh', which means the skill will produce Chinese-language output unless a caller explicitly overrides it. This is a natural-language policy concern because it imposes a specific language by default rather than offering a neutral default or explicit user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language-facing function getBookingGuide sets lang = 'zh' by default, which enforces a specific language when the caller does not explicitly choose one. This is a locale policy concern because the file provides no indication of user opt-in, language selection, or justification for making Chinese the mandatory default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing instructions repeatedly tell users to search using the Chinese phrase "济州岛with医院" and, in some channels, pair it with one English alternative, but the overall flow still prescribes a fixed locale-specific term rather than offering a general language choice. This is a natural-language locale policy concern because the content imposes a specific language/search locale without explicit user opt-in or clear region-specific justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and privacy text indicate booking can be triggered when the user '主动发起' and provides contact information, but the manifest does not define a strict, machine-verifiable consent or confirmation flow. For a medical-booking skill that collects a phone number and submits it to a third-party API, ambiguous triggering increases the risk of accidental submission of sensitive contact data or unintended booking requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file’s natural-language description and usage guidance are written only in Chinese, which can impose a specific language on users without any opt-in or indication that the skill is intentionally region-specific. Under the policy, locale or language constraints should either be optional for the user or clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This function explicitly parses a user's mobile phone number from free-form input and stores it in the result object. While the operation is part of appointment booking, this file contains no visible confirmation, notice, or comment warning that contact information is being extracted and used.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The package description is broad marketing text and does not define clear activation boundaries, supported intents, or trigger constraints. In an agent ecosystem, vague scope can cause the skill to be invoked in contexts beyond intended hospital-booking use, increasing the chance of overbroad handling of medical or booking-related requests.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
api/skill.js:25