T09 · Insecure Skill Coding Practices
- Location
skill.json:35- Finding
MCP Endpoint Identity Is Inconsistent with the Documented TLS Hostname
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This restaurant assistant is broadly purpose-aligned, but it needs review because it handles contact, delivery, order, and member data while its endpoint, authorization, and retention disclosures are inconsistent.
Install only if you trust the publisher and deployment operator. Before using it with real customers, align the MCP URL with the documented TLS hostname, resolve the privacy-retention contradictions, document user-bound authorization for order/member actions, and fix the supported-channel mismatch.
skill.json:35MCP Endpoint Identity Is Inconsistent with the Documented TLS Hostname
skill.json:213Order and Member Operations Lack Explicit User-Bound Authorization Context
PRIVACY.md:15Privacy Policy Contains Contradictory Collection and Retention Commitments
Referenced artifact was not completely inspected
> **MCP 调用方式:** 通过 MCP 协议(JSON-RPC 2.0 POST)调用。端点地址见 `skill.json` 中 `mcp_server.url` 字段。
Referenced artifact was not completely inspected
> **MCP 调用方式:** 通过 MCP 协议(JSON-RPC 2.0 POST)调用。端点地址见 `skill.json` 中 `mcp_server.url` 字段。
This privacy and safety policy is written entirely in Chinese and presents user-facing instructions, warnings, and data-handling terms without any indication that other languages are supported or that the Chinese-only requirement is optional. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale limitation is explicitly justified.
The natural-language description and all user-facing examples and instructions are written exclusively in Chinese, presenting the skill as operating in that language by default. There is no indication that users may choose another language or that the locale limitation is explicitly justified as region-specific.
The trigger examples include broad everyday phrases such as “你们店在哪”, “营业时间”, “推荐”, and similar natural-language prompts that can easily occur in adjacent conversation without a strong activation boundary. In a multi-skill or chat-integrated environment, this raises the risk of unintended invocation, causing the agent to query restaurant data or begin transactional flows when the user did not explicitly mean to engage this skill.
The fallback intent logic maps ambiguous phrases like “我饿了” and “明天聚餐” directly into menu recommendation or reservation flows without clear confirmation. This is dangerous because semantic overreach can trigger restaurant lookups, recommendations, or booking-related data collection from casual conversation, especially in always-on messaging contexts.
This manifest file says the skill supports the full restaurant service flow through natural language interaction, but it does not define specific invocation phrases, scope limits, or exclusion conditions. That broad wording can cause unintended activation for ordinary conversation about restaurants, ordering, reservations, or delivery.
Access control says allowed channels are only feishu, wechat, and qq, but the channels section also declares telegram as supported. This mismatch can lead to enforcement gaps where a supposedly disallowed channel is treated as available, potentially exposing order, member, and contact workflows on a channel that has not been properly reviewed or secured.
Delivery and reservation tools collect sensitive personal data such as phone numbers, addresses, and reservation details, yet the user-facing description does not clearly warn about this collection at the point of capability disclosure. In a messaging-channel context spanning multiple platforms, weak upfront disclosure increases privacy risk and the chance that users share sensitive information without informed consent.
The security note claims use of a named production domain and Let's Encrypt certificate, but the configured MCP endpoint is a raw IP address. This inconsistency can mislead reviewers and users about endpoint identity and certificate expectations, increasing the risk of misconfiguration, trust mistakes, or connecting to the wrong backend.
The MCP security note references www.airesistant.com while the actual MCP server is configured as https://132.33.3.231/mcp. Contradictory endpoint documentation weakens trust verification and can cause operators or users to rely on inaccurate security assumptions about certificate coverage, ownership, and traffic destination.
The top-level description frames the skill as handling restaurant lookup, ordering, reservations, delivery, and queueing, but this tool also exposes会员信息 including points, coupons, and spending history. That is a broader customer-account/loyalty capability not clearly covered by the manifest’s stated service scope.
The manifest describes full-process dining services such as query, ordering, reservation, delivery, and queueing, but this tool adds a separate评价/反馈 submission function. Feedback collection is plausible for restaurant operations, but it is not actually stated in the manifest description.
Detected: suspicious.install_untrusted_source