Back to skill

Security audit

Maejongdeok

Security checks for vulnerabilities and agentic risk

Overview

The skill matches a clinic-booking purpose, but it has review-worthy risks around personal-data submission, unsafe URL opening, exposed API tokens, and a direct APK download link.

Review before installing. Use it only if you are comfortable with a Chinese-focused BeautsGO booking workflow that sends appointment details to external services. Do not provide a phone number unless you intend it to be submitted, and prefer official app-store links over the direct APK link. The publisher should add an explicit confirmation step, replace shell exec URL opening, rotate/remove embedded tokens, and document all external destinations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
api/browser/open-url.js:18
Finding

Shell Command Injection in the URL Opener

Content
View full analysis
hostname === host || hostname.endsWith('.' + host)) } catch { return false } } async function openUrl(url) { if (!url) throw new Error('URL is required') if (!isAllowedUrl(url)) throw new Error(`URL not allowed: ${url}`) if (process.platform === 'darwin') { await execAsync(`open "${url}"`) } else if (process.platform === 'win32') { await execAsync(`start "" "${url}"`) } else { await execAsync(`xdg-open "${url}"`) } } ``` The shell execution primitive is imported and promisified at `api/browser/open-url.js:11-13`: ```js const { exec } = require('child_process') const { promisify } = require('util') const execAsync = promisify(exec) ``` ### Technical Analysis The validation routine parses the URL and checks only its protocol and hostname. However, `openUrl` does not pass the validated, normalized URL object to the operating-system utility. Instead, it interpolates the original input string into a command executed through a shell. An input can therefore have an allowed `https:` URL and hostname while still containing shell-significant characters elsewhere in the original string. Because the URL is placed inside double quotes, an injected double quote can terminate the argument and introduce shell syntax. Hostname allowlisting does not provide shell escaping. The attack surface is increased by `api/skill.js:314`, which exports the shared, mutable hospital object: ```js module.exports = { processQuery, hospital } ``` An embedding module that can import the Skill can modify URL-related fields before invoking a branch that calls `openUrl`. ### Attack ...[truncated 1152 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
api/skill.js:21
Finding

Hardcoded API Credentials in Distributed Source Code

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
api/skill.js:228
Finding

Unverified Direct APK Distribution Creates a Mutable Supply-Chain Path

Content
View full analysis
Remediation
View remediation

other

Warning
Location
api/skill.js:164
Finding

Phone Number Transmission Does Not Enforce the Declared Explicit-Consent Requirement

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating booking guidance, reading localization assets, and operating under a different apparent clinic identity than declared are not inherently malicious, but they do represent a material description-behavior mismatch. The identity inconsistency is the most concerning part, because it can mislead users about who is providing the service and where their information is going.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating booking guidance, reading localization assets, and operating under a different apparent clinic identity than declared are not inherently malicious, but they do represent a material description-behavior mismatch. The identity inconsistency is the most concerning part, because it can mislead users about who is providing the service and where their information is going.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Generating booking guidance, reading localization assets, and operating under a different apparent clinic identity than declared are not inherently malicious, but they do represent a material description-behavior mismatch. The identity inconsistency is the most concerning part, because it can mislead users about who is providing the service and where their information is going.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Generating booking guidance, reading localization assets, and operating under a different apparent clinic identity than declared are not inherently malicious, but they do represent a material description-behavior mismatch. The identity inconsistency is the most concerning part, because it can mislead users about who is providing the service and where their information is going.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
entry: api/skill.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
entry: api/skill.js

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description omits warnings that some intents open external pages or customer-service channels, which can shift users out of the expected skill environment without adequate notice. While lower severity than hidden data submission, this still increases the risk of user confusion, trust abuse, and inadvertent interaction with third-party sites.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api/skill.js (reported line 21)May include surrounding context.

js
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 17)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 30)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The main entry point sets lang = 'zh' by default, and all user-facing responses in this file are written in Chinese. This enforces a specific language/locale without offering a choice or documenting that the skill is intentionally restricted to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The booking flow transmits user-provided contact information and appointment details to a third-party API, but the user-facing prompts and success/error messages do not clearly disclose that their personal data will be sent off-platform. In a healthcare/medical-aesthetics context, even a phone number plus clinic and appointment preference is sensitive enough that silent transmission increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This file’s natural-language comments and user-facing examples assume Chinese-only interaction, such as the Chinese skill name and example inputs. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The render function defaults the language parameter to 'zh', and surrounding comments/documentation indicate the skill is oriented around Chinese output. This can violate language/locale policy when users are not explicitly given a language choice or informed that output will be in Chinese by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The function defaults lang to 'zh', which imposes a specific language choice when the caller does not explicitly provide one. This is a natural-language policy concern because the file does not indicate user choice, opt-in, or a justified locale restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The fallback text asks users to 'tell me your needs' and says it will help handle booking, which is broad enough to attract unrelated or overly general requests instead of limiting interaction to this hospital-booking workflow. In an agent-routing context, this can cause the skill to activate outside its intended scope, leading to misrouting, unintended data collection, or responses on topics the skill is not designed to handle.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The user-facing title and description are presented in Chinese, while the service itself is a Korean hospital, and the manifest does not indicate that this language choice is optional or limited to a specific audience. That creates a natural-language locale policy concern because the skill appears to enforce one language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The input schema sets 'lang' with a default of 'zh', which imposes a language choice unless the caller overrides it. This is a natural-language policy concern because the skill does not clearly present language selection as an opt-in or user choice in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description omits warnings that some intents open external pages or customer-service channels, which can shift users out of the expected skill environment without adequate notice. While lower severity than hidden data submission, this still increases the risk of user confusion, trust abuse, and inadvertent interaction with third-party sites.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's natural-language documentation is written entirely in Chinese, including the description and usage notes, with no indication that language choice is optional or region-specific. The policy requires avoiding forced language or locale constraints unless user opt-in or clear justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The URL fields explicitly force the /cn/ locale in configuration, which can be interpreted as a language/locale policy constraint embedded in the skill data. Because this JSON provides no indication of user choice, opt-in, or justification for always using the Chinese locale, it may violate the requirement to avoid forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest description explains the hospital and service area but does not indicate when the skill should activate, what user intents it is meant to handle, or any limiting conditions. In a manifest file, that absence of trigger specificity can contribute to overly broad or ambiguous invocation matching.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This manifest file describes capabilities such as '一键预约', '在线咨询', and '价格查询' but does not define specific activation phrases, scope limits, or exclusion conditions. In a manifest, this kind of broad natural-language invocation description can increase the chance of unintended activation from common user requests about booking or consultation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
api/skill.js:25