Mcdonald - 麦当劳助手
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The OpenClaw AgentSkills skill bundle is classified as benign. The `SKILL.md` file defines a McDonald's assistant that interacts with a specified MCP service (`https://mcp.mcd.cn` by default) using `curl` commands. All network calls are directed to this service, and the `MCD_TOKEN` environment variable is used for authentication to this intended service, not for exfiltration. There is no evidence of prompt injection instructions against the agent, malicious execution, data exfiltration to unauthorized endpoints, persistence mechanisms, or obfuscation. The skill's behavior is clearly aligned with its stated purpose of querying and managing McDonald's related information.
