Back to skill

Security audit

Reberry

Security checks across malware telemetry and agentic risk

Overview

This appears to be a disclosed clinic booking helper that can send appointment details to BeautsGO and open related BeautsGO pages.

Install only if you are comfortable using BeautsGO for this clinic. Before asking it to book, assume the appointment time, party size, and any phone number you provide may be sent to BeautsGO; review the details yourself because the skill may submit once enough information is present.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
The skill metadata and description present the skill as an informational hospital listing, but the documented behavior includes transactional booking submission, price querying, opening external pages, and app download flows. This mismatch can mislead users, reviewers, and policy enforcement systems about the true capabilities of the skill, increasing the risk of undisclosed data collection, unintended browser launches, and external service interaction without adequate scrutiny.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill collects personal data including contact information and appointment details, then transmits it to an external API without an explicit consent notice or clear disclosure at the point of submission. In this healthcare-adjacent context, even basic booking data is sensitive and users may not realize their information is being sent to a third-party service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
api/skill.js:25