Back to skill

Security audit

智慧餐饮

Security checks for vulnerabilities and agentic risk

Overview

This restaurant assistant is broadly purpose-aligned, but it needs review because it handles contact, delivery, order, and member data while its endpoint, authorization, and retention disclosures are inconsistent.

Install only if you trust the publisher and deployment operator. Before using it with real customers, align the MCP URL with the documented TLS hostname, resolve the privacy-retention contradictions, document user-bound authorization for order/member actions, and fix the supported-channel mismatch.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
skill.json:35
Finding

MCP Endpoint Identity Is Inconsistent with the Documented TLS Hostname

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skill.json:213
Finding

Order and Member Operations Lack Explicit User-Bound Authorization Context

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
PRIVACY.md:15
Finding

Privacy Policy Contains Contradictory Collection and Retention Commitments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
> **MCP 调用方式:** 通过 MCP 协议(JSON-RPC 2.0 POST)调用。端点地址见 `skill.json` 中 `mcp_server.url` 字段。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

md
> **MCP 调用方式:** 通过 MCP 协议(JSON-RPC 2.0 POST)调用。端点地址见 `skill.json` 中 `mcp_server.url` 字段。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This privacy and safety policy is written entirely in Chinese and presents user-facing instructions, warnings, and data-handling terms without any indication that other languages are supported or that the Chinese-only requirement is optional. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale limitation is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language description and all user-facing examples and instructions are written exclusively in Chinese, presenting the skill as operating in that language by default. There is no indication that users may choose another language or that the locale limitation is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger examples include broad everyday phrases such as “你们店在哪”, “营业时间”, “推荐”, and similar natural-language prompts that can easily occur in adjacent conversation without a strong activation boundary. In a multi-skill or chat-integrated environment, this raises the risk of unintended invocation, causing the agent to query restaurant data or begin transactional flows when the user did not explicitly mean to engage this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The fallback intent logic maps ambiguous phrases like “我饿了” and “明天聚餐” directly into menu recommendation or reservation flows without clear confirmation. This is dangerous because semantic overreach can trigger restaurant lookups, recommendations, or booking-related data collection from casual conversation, especially in always-on messaging contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest file says the skill supports the full restaurant service flow through natural language interaction, but it does not define specific invocation phrases, scope limits, or exclusion conditions. That broad wording can cause unintended activation for ordinary conversation about restaurants, ordering, reservations, or delivery.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Access control says allowed channels are only feishu, wechat, and qq, but the channels section also declares telegram as supported. This mismatch can lead to enforcement gaps where a supposedly disallowed channel is treated as available, potentially exposing order, member, and contact workflows on a channel that has not been properly reviewed or secured.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

Delivery and reservation tools collect sensitive personal data such as phone numbers, addresses, and reservation details, yet the user-facing description does not clearly warn about this collection at the point of capability disclosure. In a messaging-channel context spanning multiple platforms, weak upfront disclosure increases privacy risk and the chance that users share sensitive information without informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The security note claims use of a named production domain and Let's Encrypt certificate, but the configured MCP endpoint is a raw IP address. This inconsistency can mislead reviewers and users about endpoint identity and certificate expectations, increasing the risk of misconfiguration, trust mistakes, or connecting to the wrong backend.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The MCP security note references www.airesistant.com while the actual MCP server is configured as https://132.33.3.231/mcp. Contradictory endpoint documentation weakens trust verification and can cause operators or users to rely on inaccurate security assumptions about certificate coverage, ownership, and traffic destination.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The top-level description frames the skill as handling restaurant lookup, ordering, reservations, delivery, and queueing, but this tool also exposes会员信息 including points, coupons, and spending history. That is a broader customer-account/loyalty capability not clearly covered by the manifest’s stated service scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes full-process dining services such as query, ordering, reservation, delivery, and queueing, but this tool adds a separate评价/反馈 submission function. Feedback collection is plausible for restaurant operations, but it is not actually stated in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skill.json:40