Back to skill

Security audit

mcdonalds-mcp-order-lite

Security checks for vulnerabilities and agentic risk

Overview

This ordering skill mostly matches its McDonald's purpose, but it needs review because it can send account tokens to a configurable server and exposes account-changing actions beyond the stated flow.

Review this carefully before installing. Use only a dedicated, revocable McDonald's MCP token; ensure MCD_MCP_URL/base_url cannot be changed away from https://mcp.mcd.cn; avoid exposing mcdonalds_get_config output; and require explicit user confirmation before any order creation, coupon/points action, or cancellation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/mcd_rpc.py:14
Finding

Bearer Token Exfiltration Through an Unrestricted CLI Endpoint

Content
View full analysis
Remediation
View remediation
str: parsed = urlparse(value) if ( parsed.scheme != "https" or parsed.hostname != "mcp.mcd.cn" or parsed.port not in (None, 443) or parsed.username is not None or parsed.password is not None ): raise ValueError("MCP credentials may only be sent to https://mcp.mcd.cn") return value URL = validate_url(os.getenv("MCD_MCP_URL", OFFICIAL_URL)) ``` ]]>

T09 · Insecure Skill Coding Practices

Error
Location
client.py:42
Finding

Bearer Token Exfiltration Through an Unrestricted Client Base URL

Content
View full analysis
Dict: """ 发送API请求 """ url = urljoin(self.base_url, endpoint) try: response = self.session.request( method=method, url=url, json=data, params=params, timeout=30 ) ``` ### Technical Analysis `McDonaldsMCPClient` accepts a caller-supplied `base_url` and also reads `MCD_MCP_URL` from the environment. Neither source is validated before the client places the bearer token in session-wide headers. Every request made by the session therefore carries the McDonald's bearer credential to the resulting URL. This enables credential disclosure when an attacker can influence constructor arguments, process configuration, or environment variables. This behavior exceeds the Skill's documented requirement, which identifies `https://mcp.mcd.cn` as the server that should receive the token. The client also does not explicitly enforce TLS or the expected hostname. ### Attack Path 1. An attacker influences application configuration, startup environment, or code that c ...[truncated 1119 chars]
Remediation
View remediation
str: parsed = urlparse(url) if parsed.scheme != "https" or parsed.hostname != "mcp.mcd.cn": raise ValueError("Unapproved MCP destination") if parsed.port not in (None, 443): raise ValueError("Unexpected MCP port") return url def _make_request(self, method, endpoint, data=None, params=None): url = validate_official_url(urljoin(OFFICIAL_BASE_URL, endpoint)) headers = { "Authorization": f"Bearer {self.token}", "Content-Type": "application/json", } return self.session.request( method=method, url=url, headers=headers, json=data, params=params, timeout=30, ) ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
tools.py:644
Finding

Agent-Callable Configuration Tool Reveals a Stable Token Prefix

Content
View full analysis
Dict: """ 获取麦当劳MCP配置信息 Returns: 配置信息 """ return { 'success': True, 'config': { 'api_base_url': client.base_url, 'token_masked': client.token[:8] + '...' if client.token else '未设置', ``` ### Technical Analysis The `mcdonalds_get_config` tool returns the first eight characters of the configured bearer token. Although the value is labeled as masked, it exposes a stable token fragment rather than a constant redaction. Because this function is decorated as an agent-callable tool, the fragment can be copied into conversation history, tool traces, telemetry, debugging output, or persistent agent logs. Authentication secrets should not be partially reproduced in user-facing or agent-facing configuration output. A token prefix is generally insufficient by itself to authenticate. Nevertheless, it can support credential correlation, identify which credential is deployed in a particular environment, aid targeted searches through leaked data, and reduce uncertainty if the token format has limited entropy in its undisclosed portion. ### Attack Path 1. An attacker, untrusted prompt, or unauthorized user causes the agent to invoke `mcdonalds_get_config`. 2. The tool reads the globally initialized client's token. 3. The tool returns the first eight characters in `token_masked`. 4. The tool response is exposed to the caller or retained in chat history, telemetry, debugging logs, or agent traces. 5. The disclosed prefix is used to correlate the environment with another token leak or to identify credential reuse. ### Impact Assessment The direct impact is disclosure of eight leading characters of the MCP bearer token. This finding alone does not provide the full token or p ...[truncated 369 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (25)

Tainted flow: 'req' from os.getenv (line 35, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/mcd_rpc.py (reported line 29)May include surrounding context.

python
req.add_header("Authorization", f"Bearer {TOKEN}")
    req.add_header("Content-Type", "application/json")
    req.add_header("Accept", "application/json, text/event-stream")
    with urllib.request.urlopen(req, timeout=60) as resp:
        return json.loads(resp.read().decode())

Tainted flow: 'req' from os.getenv (line 35, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/mcd_rpc.py (reported line 39)May include surrounding context.

python
req.add_header("Authorization", f"Bearer {TOKEN}")
    req.add_header("Content-Type", "application/json")
    req.add_header("Accept", "application/json, text/event-stream")
    with urllib.request.urlopen(req, timeout=60):
        return None

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code substantially aligns with the general McDonald’s ordering/menu/store/coupon domain and uses Bearer-token-authenticated calls to the declared host, so the overall theme matches. However, there are material discrepancies. Most importantly, the description claims an MCP integration over Streamable HTTP / JSON-RPC suitable for wiring into MCP clients, while the code is just a plain Python requests client hitting REST-like endpoints and contains no JSON-RPC or MCP protocol/client integration logic. The code also omits points functionality that the description explicitly includes, and it adds undeclared capabilities such as canceling orders and fetching order history. Additionally, 'browse deliverable addresses' is not directly implemented; the closest feature is nearby store search by coordinates. These differences are sufficient to mark the description as not accurately representing the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents this skill as an MCP client/integration for the official McDonald's China server, capable of performing live delivery-order workflows and related account/order functions. The supplied code instead is a standalone NLP utility module for parsing Chinese ordering language and generating summaries/responses. While the topic domain is McDonald's ordering, the primary purpose is materially different: text understanding rather than MCP-based transaction execution or data retrieval. This is therefore a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code is broadly related to McDonald's ordering, so the general domain matches. However, the declared description is specifically about a lite MCP package for interacting with the official China MCP server and wiring it into clients, covering delivery addresses, menu/details, pricing, order creation/status, and coupons/points. The supplied code instead exposes a larger OpenClaw tool surface with several materially undeclared capabilities: cancelling orders, NLP-based intent parsing, a smart assistant, and combo suggestions. It also includes a configuration endpoint that reveals API base URL and a masked token, which is not described. Conversely, some declared capabilities are missing or only partially supported in this chunk: no visible points handling, no real client wiring/integration logic, and no explicit deliverable-address browsing beyond nearby geolocation-based store search. Because there are multiple undeclared functional capabilities and some declared functions are not represented, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares broad network/MCP/env-capable behavior but does not constrain tool scope with explicit permissions or allowed-tools. In an agent ecosystem, missing scope boundaries can let the skill invoke sensitive capabilities more broadly than users or host runtimes expect, especially when bearer-token and remote-order workflows are involved.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly handles delivery addresses, order details, and bearer-authenticated remote requests, yet the description provides no privacy warning or data-handling notice. Users may disclose sensitive location and purchasing information without understanding that it will be transmitted to a third-party service, increasing privacy and consent risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises account-affecting functions such as auto-claiming coupons, coupon wallet interactions, points account access, and points-mall ordering without warning users that these actions can change account state or consume benefits. In an agent context, insufficient warning can lead to unintended financial or account consequences if invoked automatically or with ambiguous consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Allowing the base URL to be overridden by constructor input or an environment variable means the bearer token and any user/order data can be sent to an arbitrary server instead of the claimed official endpoint. In an agent or plugin environment, this materially increases the risk of credential exfiltration, SSRF-like internal access, or silent redirection to a malicious MCP-compatible service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The find_stores method sends latitude and longitude to the remote API to locate nearby stores. Although this is functionally expected, the code provides no explicit disclosure that precise location data is being transmitted, beyond a neutral parameter description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The create_order method accepts user_info and delivery_info containing personal details such as name, phone, and delivery data, then sends them via HTTP in the request body. While the docstring describes the parameters, there is no explicit warning or disclosure that sensitive personal data will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes browsing addresses, querying menu items, inspecting meal details, calculating price, creating a delivery order, querying order status, and checking coupons/points. This file additionally implements cancel_order and get_order_history, which are materially different account/order-management capabilities not mentioned in the stated skill scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code's natural-language descriptions, keyword triggers, and user-facing responses are entirely hard-coded in Chinese, which effectively forces a specific language/locale. The file does not offer any user opt-in, language selection, or documentation that the skill is intentionally limited to a Chinese-only regional deployment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation provides concrete create-order inputs and a tested ordering flow for a live production commerce endpoint without an explicit requirement to obtain fresh user confirmation immediately before placing an order. In an agent setting, this increases the risk of unintended real-world purchases if the model treats the example as an actionable next step rather than a sensitive transaction boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file performs a network POST to a remote endpoint and includes a bearer token in the Authorization header, transmitting both credentials and user-provided parameters. Aside from a token-missing error, there is no confirmation prompt, logging, or explanatory comment/docstring warning that data and credentials will be sent to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The store-lookup function takes precise latitude and longitude and sends them to a backend without an explicit disclosure or consent step. Precise location is sensitive data, and in an agent workflow it may be transmitted more broadly than the user expects, enabling unnecessary tracking or exposure of whereabouts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The order-creation tool collects and transmits personal data such as name, phone number, and delivery address, but this file provides no explicit consent notice or confirmation boundary before sending it to the remote MCP service. In agent contexts, users may not realize that free-form chat content is being turned into externally transmitted PII and a live order request.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file exposes an order-cancellation capability that is not declared in the skill metadata/manifest scope presented to users. This scope drift is dangerous because downstream agents or users may authorize or install the skill expecting read/browse/order features, while the skill can also perform destructive account actions that may lead to unauthorized cancellations or refunds.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Order cancellation is a potentially irreversible state-changing action, yet the tool performs it directly with no built-in confirmation or warning. In an agent setting, ambiguity, prompt injection, or misunderstanding could cause unintended cancellation of a real customer order and possible financial or service disruption.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The configuration tool returns a masked prefix of the bearer token (client.token[:8] + '...') to callers. Even partial secret disclosure weakens token confidentiality, aids credential correlation and debugging leakage, and can expose sensitive material to untrusted clients, logs, screenshots, or prompt history.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The get_menu method sets the default language to 'zh-CN', and the file-level descriptions are also Chinese-only, which indicates the skill is biased toward a specific locale by default. The policy requires user choice or clear justification for forcing a language/locale; no opt-in or region-specific justification is provided here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The saved-address example highlights privacy-sensitive fields such as contactName, phone, and fullAddress but does not warn implementers to minimize display, logging, retention, or reuse of that data. In an MCP/agent integration, this can lead to unnecessary exposure of personal information in chat transcripts, debug logs, or downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file reads MCD_MCP_TOKEN from the environment and uses it for authenticated requests, which is a sensitive credential-handling operation under the warning criteria for code files. The script tells the user to set the variable if missing, but it does not explicitly disclose in its documentation or runtime output that the token will be attached to outbound requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

mcdonalds_view_menu sets language: str = "zh-CN" and the surrounding user-facing text throughout the file is Chinese, indicating a fixed locale bias. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest presents the skill as a thin MCP integration for McDonald's operations and client wiring, but this file adds higher-level conversational intent recognition and assistant orchestration capabilities. These are functional additions beyond the manifest's stated operational scope, even if related to ordering.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.