Back to skill

Security audit

eShop

Security checks for vulnerabilities and agentic risk

Overview

This shopping skill is mostly purpose-aligned, but it can create or close orders and use saved account data without a clear confirmation boundary.

Install only if you trust the configured MCP endpoints and are comfortable with the skill using shopping tokens, saved addresses, coupons, points, and order-management actions. Before use, require explicit confirmation for every order or cancellation and avoid setting configurable endpoint variables to untrusted hosts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
delivery/merchants/mcd.md:42
Finding

Authentication Token Exposure Through a Configurable McDonald's MCP Endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
ecommerce/platforms/luogang.md:34
Finding

User Authentication Token Can Be Sent to an Unvalidated Luogang MCP Endpoint

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
ecommerce/platforms/luogang.md:24
Finding

Order Creation May Proceed Without a Consistent Explicit Confirmation Boundary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- aliases: `麦当劳`, `McDonald's`, `McDonald`, `mcd`, `mcdonalds`
  target: `delivery/merchants/mcd.md`

<!-- - aliases: `肯德基`, `KFC`, `kfc`
  target: `delivery/kfc.md`

- aliases: `必胜客`, `Pizza Hut`, `pizzahut`

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description authorizes activation on very broad shopping intent, especially when the user merely mentions '骆岗/骆岗门市部/骆岗电商'. Over-broad routing can cause the assistant to invoke this commerce skill in unrelated conversations, increasing the chance of unintended data access, external calls, or transactional actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs direct order creation with the default shipping address and says not to ask the user when a token is available. This enables data-affecting actions using stored personal information without an explicit confirmation checkpoint, which can result in unintended purchases, privacy exposure, or unauthorized transactions from ambiguous prompts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger example “看看有什么吃的” is very broad and could match casual conversation rather than a clear skill-invocation intent. The document does not provide exclusion conditions or negative examples to narrow when this routing should or should not activate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Examples like “我要买东西”, “帮我找商品”, and “看看某个平台上的商品” are generic shopping-related phrases that can occur in many contexts. The file does not define stricter trigger boundaries or exclusions, making activation scope ambiguous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest text forces a single language/locale in the user-facing description, but it does not state that the skill is China-specific or offer an alternative language. This can violate language/locale policy when users are not given an explicit opt-in or justified regional constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The skill directs the agent to send authenticated requests containing a bearer token to an external endpoint, which results in transmission of sensitive user/account data and credentials outside the local environment. This is more dangerous because the endpoint is partially configurable via MCD_MCP_URL, creating SSRF/exfiltration risk if that environment variable is altered or misconfigured, even though the default target appears legitimate.

Content

Scanner excerpt · delivery/merchants/mcd.md (reported line 42)May include surrounding context.

API Call Pattern

All tools are invoked via curl to the MCP endpoint:

bash
curl -s -X POST "${MCD_MCP_URL:-https://mcp.mcd.cn}" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
74% confidence
Finding

The skill is designed to send user-supplied queries and account-linked parameters to an external MCP endpoint, which is an actual data transmission boundary. In this shopping context such transmission is expected, but it remains security-relevant because product queries, tokens, addresses, and order details may leave the host environment and reach a remote service.

Content

Scanner excerpt · ecommerce/platforms/luogang.md (reported line 39)May include surrounding context.

调用方式

bash
curl -s -X POST "$LUOGANG_MCP_HTTP_URL" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","method":"tools/call","params":{"name":"<工具名>","arguments":{<参数>}},"id":1}'

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Generic trigger phrases like '买鞋子' or '有没有外套' are common everyday speech and may overlap with casual discussion, recommendations, or non-transactional queries. This raises the risk of invoking external shopping tools and transmitting user queries when the user did not intend to engage the Luogang platform specifically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The address and order flows omit any privacy guardrails despite handling sensitive personal data such as recipient name, phone number, and shipping address. Without masking and warning requirements, the skill may expose or echo private data in chat output more broadly than necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Using an ambiguous cancellation trigger like '不要了' is dangerous because it can appear in many contexts and could be misinterpreted as authorization to close an order. In a transactional skill, broad intent matching can lead to destructive account actions without sufficiently clear user consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L304-L305 明确说明 create_order 应“使用 sku_id 和 num,不经过购物车”,且前文 L177-L181、L191-L193 也将 sku_id 和 num 作为下单参数。但紧接着的实际调用示例在 L317 使用的是 sku_list 数组,和前述说明的接口用法直接冲突,容易导致代理按错误参数格式执行下单。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language content, trigger examples, and clarification prompts are entirely in Chinese, with no indication that users may choose another language. This can violate language/locale policy when a skill implicitly constrains interaction language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

文档前面将麦当劳映射为 delivery/merchants/mcd.md(L87、L107),但示例“我要点麦当劳”却写成加载 delivery/mcd.md。这不是单纯省略细节,而是对实际路由目标给出了互相冲突的说明,可能误导实现或审计者对技能实际加载范围的理解。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

Routing Index 将骆岗平台目标声明为 ecommerce/platforms/luogang.md(L126-L127),但示例“去骆岗看看耳机”写成加载 ecommerce/luogang.md。该文档内部对同一实体的目标文件给出两个不同位置,构成意图/文档与实际路由说明的直接矛盾。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The communication guideline says to 'Use friendly, conversational Chinese,' which imposes a specific language on all interactions. This is a natural-language policy concern because the file does not offer the user a language choice or indicate opt-in for Chinese-only responses.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

L027-L028 规定“直接创建订单”“使用默认收货地址,不询问用户”,表达的是明确的自动化执行意图。但完整流程示例中 L299-L301 又要求“确认购买2张吗?/用户:确认”,与前述交互原则形成直接冲突,导致技能意图和执行指导不一致。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.