Back to skill

Security audit

Reberry

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a clinic-booking purpose, but it can send phone and appointment details externally without the explicit confirmation it promises and ships unsafe local command-opening code.

Review this skill before installing. It is intended for Reberry clinic booking through BeautsGO, but users should know that a booking message with a date and phone number may be submitted to the external booking API immediately. The publisher should add a clear confirmation step, remove hardcoded API tokens, fix the shell-based URL opener, restrict language file loading, and clean up mismatched clinic comments.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
api/browser/open-url.js:18
Finding

Shell Command Injection in URL-Opening Utility

Content
View full analysis
hostname === host || hostname.endsWith('.' + host)) } catch { return false } } async function openUrl(url) { if (!url) throw new Error('URL is required') if (!isAllowedUrl(url)) throw new Error(`URL not allowed: ${url}`) if (process.platform === 'darwin') { await execAsync(`open "${url}"`) } else if (process.platform === 'win32') { await execAsync(`start "" "${url}"`) } else { await execAsync(`xdg-open "${url}"`) } } ``` ### Technical Analysis The URL validator checks only the parsed protocol and hostname. It does not prevent shell metacharacters or command substitutions in the URL path, query, or fragment. The validated string is subsequently interpolated into a command passed to `child_process.exec`. The `exec` API invokes a system shell. Wrapping the URL in double quotes does not prevent all shell expansion; on Unix-like systems, constructs such as `$(command)` and backtick command substitutions remain active inside double-quoted strings. Although the normal `processQuery` flow currently generates URLs from static hospital data, `openUrl` is exported and the file also exposes a command-line interface that directly consumes `process.argv[2]`. Exploitation therefore requires an attacker to control an argument passed to the exported function or CLI. ### Attack Path 1. An attacker gains control over a URL supplied to the exported `openUrl` function or the command-line entry point. 2. The attacker supplies an HTTPS URL whose hostname passes the allowlist but whose path contains shell syntax, for example: ```text https://i.beautsgo.com/$(id) ``` 3. `new URL()` reports the pe ...[truncated 849 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
api/skill.js:21
Finding

API Credentials Embedded in Distributable Source Code

Content
View full analysis
{ const url = new URL(BOOKING_API_URL) const body = JSON.stringify(payload) const options = { hostname: url.hostname, path: url.pathname, method: 'POST', headers: { 'Content-Type': 'application/json', 'X-Open-Token': BOOKING_API_TOKEN, }, } ``` ```js function queryProjectPrice(hId, keyword) { return new Promise((resolve, reject) => { const urlStr = `${PRICE_API_URL}?h_id=${hId}&keywords=${encodeURIComponent(keyword)}` const url = new URL(urlStr) const options = { hostname: url.hostname, path: url.pathname + url.search, port: url.port, method: 'GET', headers: { 'Authorization': PRICE_API_TOKEN }, } ``` ### Technical Analysis The booking and price API tokens are stored directly in source code and are included in outgoing authentication headers. Any party able to download, inspect, cache, or redistribute the Skill package can recover these values without executing the Skill. The booking token resembles an unsafe fixed placeholder, while the price token has the structure of a credential. Regardless of whether either token is currently active, source-embedded shared credentials cannot be kept confidential or safely rotated per deployment. ### Attack Path 1. An attacker obtains the publicly or internally distributed Skill package. 2. The attacker reads `api/skill.js` and extracts the token constant ...[truncated 828 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
core/renderer.js:31
Finding

Path Traversal Through Unvalidated Language Identifier

Content
View full analysis
Remediation
View remediation

other

Warning
Location
api/skill.js:164
Finding

Phone Number Transmitted Without the Declared Explicit Consent Step

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill actually submits appointment requests to external APIs and opens external pages without clearly declaring those capabilities, users and host platforms may be misled about data handling and outbound actions. In a medical-booking context, hidden transmission of personal details to third-party booking systems can create privacy, consent, and trust risks even if the behavior is intended functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill actually submits appointment requests to external APIs and opens external pages without clearly declaring those capabilities, users and host platforms may be misled about data handling and outbound actions. In a medical-booking context, hidden transmission of personal details to third-party booking systems can create privacy, consent, and trust risks even if the behavior is intended functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill actually submits appointment requests to external APIs and opens external pages without clearly declaring those capabilities, users and host platforms may be misled about data handling and outbound actions. In a medical-booking context, hidden transmission of personal details to third-party booking systems can create privacy, consent, and trust risks even if the behavior is intended functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the skill actually submits appointment requests to external APIs and opens external pages without clearly declaring those capabilities, users and host platforms may be misled about data handling and outbound actions. In a medical-booking context, hidden transmission of personal details to third-party booking systems can create privacy, consent, and trust risks even if the behavior is intended functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the skill actually submits appointment requests to external APIs and opens external pages without clearly declaring those capabilities, users and host platforms may be misled about data handling and outbound actions. In a medical-booking context, hidden transmission of personal details to third-party booking systems can create privacy, consent, and trust risks even if the behavior is intended functionality.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
entry: api/skill.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
entry: api/skill.js

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a skill for 'reberry医院 明洞店' and related dermatology services, but the file is explicitly documented and implemented to open only BeautsGO platform URLs. That indicates the actual behavior is tied to a third-party platform/domain rather than directly to the named Reberry clinic purpose described in the manifest.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes the skill as serving reberry医院 明洞店, but the file header comment says "JD皮肤科预约技能" and documents the module as a JD clinic booking entrypoint. This is an active contradiction in documentation about the skill's target entity, which can mislead maintainers and auditors about what service the code is intended to support.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api/skill.js (reported line 21)May include surrounding context.

js
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 17)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 30)May include surrounding context.

json
// ── 预约接口配置 ─────────────────────────────────────────────────────────────

const BOOKING_API_URL = 'https://api.yestokr.com/api/Appointment/saveFromSkill'
const BOOKING_API_TOKEN = 'beautsgo-openapi-fixed-token-change-me'

const PRICE_API_URL = 'https://apis.beise.com:50144/c5d1dcbc/ProjectDraft/search'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The processQuery function sets lang = 'zh' by default, and the user-facing strings throughout the file are Chinese. This forces a locale/language choice unless the caller explicitly overrides it, which is a natural-language policy concern under the stated rules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The booking flow transmits user-supplied contact information and appointment details to a third-party API without a clear prior disclosure or consent notice at the point of collection. In a healthcare-related booking context, this is more sensitive because phone numbers and treatment/visit timing can reveal personal or medical-interest information.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The top-level comment explicitly identifies the skill as "JD皮肤科预约技能", while the manifest says the skill is "reberry-booking" for reberry医院 明洞店. This is an active contradiction in documented intent, suggesting the file was copied from a different clinic skill and may not align with the declared skill identity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The render function sets the default language to 'zh' and immediately loads that locale when no user choice is provided. This is a natural-language locale policy concern because the skill forces a specific language by default rather than explicitly offering or requiring user selection.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The file header says the script opens URLs in the system browser and only allows BeautsGO platform domains. In the context of this skill, that documentation points to a different operational target than the manifest's Reberry clinic description, creating an intent-level contradiction between code documentation and declared skill purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file-level description and function documentation are entirely in Chinese and define the skill around Chinese-language inputs such as Chinese trigger phrases and date terms. There is no indication that users may choose another language or locale, which can constitute a language/locale policy issue when no opt-in is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file header says this is a 'JD皮肤科预约技能' rendering layer, while the manifest describes the skill as 'reberry-booking' for reberry医院 明洞店. That documentation does not match the stated skill identity and can mislead reviewers about which clinic this renderer is intended to support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The function defaults the lang parameter to 'zh', which imposes a specific locale when the caller does not explicitly choose one. This is a natural-language policy concern because the file does not indicate an opt-in or user choice for language selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The title and description fields are entirely in Chinese, which imposes a specific language on users through natural-language metadata. Under the policy, locale or language constraints should either be optional, user-selectable, or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
api/skill.js:25