T08 · Insecure Dependencies
- Location
scripts/start_mcp.sh:73- Finding
Unpinned Third-Party MCP Package Is Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent massage booking assistant, but its setup and test utilities can run unpinned code and submit live bookings with phone numbers, so users should review it carefully before installing.
Install only if you trust the Lann remote service and the lann-mcp-server package source. Avoid running the bundled test scripts against production, pin or verify any MCP package before use, and require clear user confirmation before sending phone numbers or booking details off-platform.
scripts/start_mcp.sh:73Unpinned Third-Party MCP Package Is Downloaded and Executed
scripts/test_booking.py:77Test Suites Submit Real Production Bookings and Expose Phone Numbers in Output
A description-behavior mismatch is a real security concern because reviewers and users may trust the declared purpose while the skill also introduces undeclared operational capabilities like managing MCP server runtime, dependency installation, or exposing interfaces. Hidden setup or environment-management behavior can expand privileges and create unexpected execution paths beyond a simple booking assistant.
A description-behavior mismatch is a real security concern because reviewers and users may trust the declared purpose while the skill also introduces undeclared operational capabilities like managing MCP server runtime, dependency installation, or exposing interfaces. Hidden setup or environment-management behavior can expand privileges and create unexpected execution paths beyond a simple booking assistant.
A description-behavior mismatch is a real security concern because reviewers and users may trust the declared purpose while the skill also introduces undeclared operational capabilities like managing MCP server runtime, dependency installation, or exposing interfaces. Hidden setup or environment-management behavior can expand privileges and create unexpected execution paths beyond a simple booking assistant.
The README presents the skill's operational guidance entirely in Chinese, including user interaction examples and instructions, but does not state that the skill is Chinese-language only or offer an alternative language option. This can violate language/locale policy when a skill effectively forces one language without user opt-in or documented justification.
The documentation explicitly instructs users to send booking data, including a phone number, to an external HTTPS endpoint. External transmission is expected for a booking skill, but it still creates a real privacy and data-governance risk because sensitive user information leaves the local assistant environment and is shared with a remote service.
使用 curl 或其他 HTTP 客户端直接调用预约接口:
curl -X POST "https://open.lannlife.com/mcp/book/create" \
The README includes a direct booking example that sends a user's phone number to an external API endpoint, but the example is presented as a routine usage pattern without a clear, proximate warning that personally identifiable information will be transmitted off-platform. In an AI skill context, this can normalize collecting and forwarding sensitive user data before the user meaningfully understands where it is going or consents to that transfer.
The skill describes network access and MCP/HTTP interactions but does not declare any explicit tool scope such as allowed network destinations or permitted tools. That weakens sandboxing and review because a host may grant broader network or shell capability than the booking workflow actually needs, increasing the blast radius if the skill or a dependency is modified or abused.
The skill asks the user for a mobile phone number and transmits it to a remote API, but it does not present a clear just-in-time privacy notice before collection and transfer. This creates a real privacy risk because users may disclose personal data without understanding that it will leave the local assistant context and be sent to a third-party service.
This code path sends user-supplied booking details, including a phone number, to an external internet endpoint. External transmission is expected for a booking skill, but it is still security-relevant because it exposes personal data to a third-party service and creates dependency on the trustworthiness and transport protections of that remote endpoint.
import requests
response = requests.post(
"https://open.lannlife.com/mcp/book/create",
headers={"Content-Type": "application/json"},
json={
This code path sends user-supplied booking details, including a phone number, to an external internet endpoint. External transmission is expected for a booking skill, but it is still security-relevant because it exposes personal data to a third-party service and creates dependency on the trustworthiness and transport protections of that remote endpoint.
import requests
response = requests.post(
"https://open.lannlife.com/mcp/book/create",
headers={"Content-Type": "application/json"},
json={
The entire skill file is written as user-facing Chinese message templates, including fixed reply instructions such as replying with Chinese words like "确认" or asking for store/service information in Chinese. There is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-only regional context, which may violate language/locale policy requirements.
The API documentation requires sending a user's mobile phone number to a remote third-party endpoint to complete a booking, but it does not state that the number will be transmitted off-platform or require explicit user-facing consent. In a booking skill, this is a real privacy risk because phone numbers are personal data and users may not realize they are being shared with an external service.
The API requires an 11-digit mainland China mobile number and presents the interface/documentation entirely in Chinese, which reflects a fixed locale assumption. Under the policy, locale constraints should either offer user opt-in/choice or be clearly documented as a justified region-specific limitation.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST "https://open.lannlife.com/mcp/book/create" \
-H "Content-Type: application/json" \
-d '{
"mobile": "13812345678",
The skill manifest describes end-user capabilities for querying stores, querying SPA services, and making bookings. This script does not implement any of those operations directly; it only checks for Node/npm, prints setup instructions, starts a separate server, and writes MCP client configuration. That is a meaningful mismatch between the described skill behavior and the actual code in this file.
Nearly all user-facing help text, status messages, and usage instructions in the script are hard-coded in Chinese. This imposes a specific language on users without offering a language choice or documenting that the script is intentionally region-specific.
The start_http_mode function documents and prints that it will start a local HTTP service at http://$host:$port, then runs npm start in a local server directory. However, generate_config for http emits a client config pointing to https://open.lannlife.com/mcp instead of the local host/port service. This is an active contradiction between the script's documented local HTTP mode and the configuration it generates for that mode.
This shell script unconditionally writes to mcp-config.json using shell redirection, which can overwrite an existing file in the current directory. Although it prints a success message afterward, there is no prior warning, confirmation prompt, or comment disclosing the potential data-loss behavior before the write occurs.
This test script sends booking data, including a phone number, to an external production endpoint and also prints the payload locally. In skill/repository context, that creates a real data-exfiltration and privacy risk because running the test can transmit personal data off-host and may generate unintended real bookings against a live service.
print(json.dumps(payload, indent=2, ensure_ascii=False))
try:
response = requests.post(
API_ENDPOINT,
headers=HEADERS,
json=payload,
This second POST path also transmits booking-related data externally to the live API, here with intentionally incomplete parameters for negative testing. Even though the payload is smaller, it still discloses user/store data to a third-party endpoint and can exercise production-side behavior unexpectedly, which is risky in an agent skill context.
print(json.dumps(payload, indent=2, ensure_ascii=False))
try:
response = requests.post(
API_ENDPOINT,
headers=HEADERS,
json=payload,
The script performs an outbound POST to an external remote service and includes booking details in the request body. In this skill context, that behavior is expected for booking functionality, but it is still security-relevant because execution causes real network transmission of potentially sensitive data and operational side effects against a live service.
}
EOF
response=$(curl -s -w "\n%{http_code}" -X POST "$API_ENDPOINT" \
-H "Content-Type: application/json" \
-d "{
\"mobile\": \"$mobile\",
The script sends booking data, including a phone number, to a live production endpoint and even includes a plausibly real-looking mobile number in the test data. Running it can transmit personal data and may create actual reservations without clearly warning the operator or requiring explicit confirmation of the privacy and side effects.
The manifest description is written entirely in Chinese and presents the skill as a Chinese-language booking skill without indicating that users may choose another language or locale. Under the policy for natural-language constraints, this can be a locale/language restriction unless explicitly documented as region-specific or opt-in.
This JSON file contains all user-facing textual values such as store names, addresses, and transit directions exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy concern.
The manifest says the skill covers stores in '上海、杭州、成都等多城市', implying a multi-city footprint, but this data file specifically includes additional cities such as 苏州 (L379-L396), 武汉 (L219-L224), 宁波 (L571-L576), and 深圳 (L595-L600) that are not reflected in the example city list. This is a mild description-behavior mismatch because the code/data scope is broader than the concrete geographic examples presented in the manifest.
No suspicious patterns detected.