T09 · Insecure Skill Coding Practices
- Location
delivery/merchants/mcd.md:42- Finding
Authentication Token Exposure Through a Configurable McDonald's MCP Endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This shopping skill is mostly purpose-aligned, but it can create or close orders and use saved account data without a clear confirmation boundary.
Install only if you trust the configured MCP endpoints and are comfortable with the skill using shopping tokens, saved addresses, coupons, points, and order-management actions. Before use, require explicit confirmation for every order or cancellation and avoid setting configurable endpoint variables to untrusted hosts.
delivery/merchants/mcd.md:42Authentication Token Exposure Through a Configurable McDonald's MCP Endpoint
ecommerce/platforms/luogang.md:34User Authentication Token Can Be Sent to an Unvalidated Luogang MCP Endpoint
ecommerce/platforms/luogang.md:24Order Creation May Proceed Without a Consistent Explicit Confirmation Boundary
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
- aliases: `麦当劳`, `McDonald's`, `McDonald`, `mcd`, `mcdonalds`
target: `delivery/merchants/mcd.md`
<!-- - aliases: `肯德基`, `KFC`, `kfc`
target: `delivery/kfc.md`
- aliases: `必胜客`, `Pizza Hut`, `pizzahut`
The skill description authorizes activation on very broad shopping intent, especially when the user merely mentions '骆岗/骆岗门市部/骆岗电商'. Over-broad routing can cause the assistant to invoke this commerce skill in unrelated conversations, increasing the chance of unintended data access, external calls, or transactional actions.
The skill explicitly instructs direct order creation with the default shipping address and says not to ask the user when a token is available. This enables data-affecting actions using stored personal information without an explicit confirmation checkpoint, which can result in unintended purchases, privacy exposure, or unauthorized transactions from ambiguous prompts.
The trigger example “看看有什么吃的” is very broad and could match casual conversation rather than a clear skill-invocation intent. The document does not provide exclusion conditions or negative examples to narrow when this routing should or should not activate.
Examples like “我要买东西”, “帮我找商品”, and “看看某个平台上的商品” are generic shopping-related phrases that can occur in many contexts. The file does not define stricter trigger boundaries or exclusions, making activation scope ambiguous.
The manifest text forces a single language/locale in the user-facing description, but it does not state that the skill is China-specific or offer an alternative language. This can violate language/locale policy when users are not given an explicit opt-in or justified regional constraint.
The skill directs the agent to send authenticated requests containing a bearer token to an external endpoint, which results in transmission of sensitive user/account data and credentials outside the local environment. This is more dangerous because the endpoint is partially configurable via MCD_MCP_URL, creating SSRF/exfiltration risk if that environment variable is altered or misconfigured, even though the default target appears legitimate.
All tools are invoked via curl to the MCP endpoint:
curl -s -X POST "${MCD_MCP_URL:-https://mcp.mcd.cn}" \
The skill is designed to send user-supplied queries and account-linked parameters to an external MCP endpoint, which is an actual data transmission boundary. In this shopping context such transmission is expected, but it remains security-relevant because product queries, tokens, addresses, and order details may leave the host environment and reach a remote service.
curl -s -X POST "$LUOGANG_MCP_HTTP_URL" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","method":"tools/call","params":{"name":"<工具名>","arguments":{<参数>}},"id":1}'
Generic trigger phrases like '买鞋子' or '有没有外套' are common everyday speech and may overlap with casual discussion, recommendations, or non-transactional queries. This raises the risk of invoking external shopping tools and transmitting user queries when the user did not intend to engage the Luogang platform specifically.
The address and order flows omit any privacy guardrails despite handling sensitive personal data such as recipient name, phone number, and shipping address. Without masking and warning requirements, the skill may expose or echo private data in chat output more broadly than necessary.
Using an ambiguous cancellation trigger like '不要了' is dangerous because it can appear in many contexts and could be misinterpreted as authorization to close an order. In a transactional skill, broad intent matching can lead to destructive account actions without sufficiently clear user consent.
L304-L305 明确说明 create_order 应“使用 sku_id 和 num,不经过购物车”,且前文 L177-L181、L191-L193 也将 sku_id 和 num 作为下单参数。但紧接着的实际调用示例在 L317 使用的是 sku_list 数组,和前述说明的接口用法直接冲突,容易导致代理按错误参数格式执行下单。
The natural-language content, trigger examples, and clarification prompts are entirely in Chinese, with no indication that users may choose another language. This can violate language/locale policy when a skill implicitly constrains interaction language without opt-in or documented justification.
文档前面将麦当劳映射为 delivery/merchants/mcd.md(L87、L107),但示例“我要点麦当劳”却写成加载 delivery/mcd.md。这不是单纯省略细节,而是对实际路由目标给出了互相冲突的说明,可能误导实现或审计者对技能实际加载范围的理解。
Routing Index 将骆岗平台目标声明为 ecommerce/platforms/luogang.md(L126-L127),但示例“去骆岗看看耳机”写成加载 ecommerce/luogang.md。该文档内部对同一实体的目标文件给出两个不同位置,构成意图/文档与实际路由说明的直接矛盾。
The communication guideline says to 'Use friendly, conversational Chinese,' which imposes a specific language on all interactions. This is a natural-language policy concern because the file does not offer the user a language choice or indicate opt-in for Chinese-only responses.
L027-L028 规定“直接创建订单”“使用默认收货地址,不询问用户”,表达的是明确的自动化执行意图。但完整流程示例中 L299-L301 又要求“确认购买2张吗?/用户:确认”,与前述交互原则形成直接冲突,导致技能意图和执行指导不一致。
No suspicious patterns detected.