Back to skill

Security audit

蘭(Lann)泰式按摩预约技能

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent massage booking assistant, but its setup and test utilities can run unpinned code and submit live bookings with phone numbers, so users should review it carefully before installing.

Install only if you trust the Lann remote service and the lann-mcp-server package source. Avoid running the bundled test scripts against production, pin or verify any MCP package before use, and require clear user confirmation before sending phone numbers or booking details off-platform.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/start_mcp.sh:73
Finding

Unpinned Third-Party MCP Package Is Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/test_booking.py:77
Finding

Test Suites Submit Real Production Bookings and Expose Phone Numbers in Output

Content
View full analysis
&1) ``` ### Technical An ...[truncated 2414 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A description-behavior mismatch is a real security concern because reviewers and users may trust the declared purpose while the skill also introduces undeclared operational capabilities like managing MCP server runtime, dependency installation, or exposing interfaces. Hidden setup or environment-management behavior can expand privileges and create unexpected execution paths beyond a simple booking assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

A description-behavior mismatch is a real security concern because reviewers and users may trust the declared purpose while the skill also introduces undeclared operational capabilities like managing MCP server runtime, dependency installation, or exposing interfaces. Hidden setup or environment-management behavior can expand privileges and create unexpected execution paths beyond a simple booking assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

A description-behavior mismatch is a real security concern because reviewers and users may trust the declared purpose while the skill also introduces undeclared operational capabilities like managing MCP server runtime, dependency installation, or exposing interfaces. Hidden setup or environment-management behavior can expand privileges and create unexpected execution paths beyond a simple booking assistant.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README presents the skill's operational guidance entirely in Chinese, including user interaction examples and instructions, but does not state that the skill is Chinese-language only or offer an alternative language option. This can violate language/locale policy when a skill effectively forces one language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The documentation explicitly instructs users to send booking data, including a phone number, to an external HTTPS endpoint. External transmission is expected for a booking skill, but it still creates a real privacy and data-governance risk because sensitive user information leaves the local assistant environment and is shared with a remote service.

Content

Scanner excerpt · README.md (reported line 145)May include surrounding context.

方式 2:直接调用 API

使用 curl 或其他 HTTP 客户端直接调用预约接口:

bash
curl -X POST "https://open.lannlife.com/mcp/book/create" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README includes a direct booking example that sends a user's phone number to an external API endpoint, but the example is presented as a routine usage pattern without a clear, proximate warning that personally identifiable information will be transmitted off-platform. In an AI skill context, this can normalize collecting and forwarding sensitive user data before the user meaningfully understands where it is going or consents to that transfer.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes network access and MCP/HTTP interactions but does not declare any explicit tool scope such as allowed network destinations or permitted tools. That weakens sandboxing and review because a host may grant broader network or shell capability than the booking workflow actually needs, increasing the blast radius if the skill or a dependency is modified or abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill asks the user for a mobile phone number and transmits it to a remote API, but it does not present a clear just-in-time privacy notice before collection and transfer. This creates a real privacy risk because users may disclose personal data without understanding that it will leave the local assistant context and be sent to a third-party service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This code path sends user-supplied booking details, including a phone number, to an external internet endpoint. External transmission is expected for a booking skill, but it is still security-relevant because it exposes personal data to a third-party service and creates dependency on the trustworthiness and transport protections of that remote endpoint.

Content

Scanner excerpt · SKILL.md (reported line 310)May include surrounding context.

python
import requests

response = requests.post(
    "https://open.lannlife.com/mcp/book/create",
    headers={"Content-Type": "application/json"},
    json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This code path sends user-supplied booking details, including a phone number, to an external internet endpoint. External transmission is expected for a booking skill, but it is still security-relevant because it exposes personal data to a third-party service and creates dependency on the trustworthiness and transport protections of that remote endpoint.

Content

Scanner excerpt · SKILL.md (reported line 310)May include surrounding context.

python
import requests

response = requests.post(
    "https://open.lannlife.com/mcp/book/create",
    headers={"Content-Type": "application/json"},
    json={

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill file is written as user-facing Chinese message templates, including fixed reply instructions such as replying with Chinese words like "确认" or asking for store/service information in Chinese. There is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-only regional context, which may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The API documentation requires sending a user's mobile phone number to a remote third-party endpoint to complete a booking, but it does not state that the number will be transmitted off-platform or require explicit user-facing consent. In a booking skill, this is a real privacy risk because phone numbers are personal data and users may not realize they are being shared with an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The API requires an 11-digit mainland China mobile number and presents the interface/documentation entirely in Chinese, which reflects a fixed locale assumption. Under the policy, locale constraints should either offer user opt-in/choice or be clearly documented as a justified region-specific limitation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api_reference.md (reported line 30)May include surrounding context.

请求示例

bash
curl -X POST "https://open.lannlife.com/mcp/book/create" \
  -H "Content-Type: application/json" \
  -d '{
    "mobile": "13812345678",

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill manifest describes end-user capabilities for querying stores, querying SPA services, and making bookings. This script does not implement any of those operations directly; it only checks for Node/npm, prints setup instructions, starts a separate server, and writes MCP client configuration. That is a meaningful mismatch between the described skill behavior and the actual code in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Nearly all user-facing help text, status messages, and usage instructions in the script are hard-coded in Chinese. This imposes a specific language on users without offering a language choice or documenting that the script is intentionally region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The start_http_mode function documents and prints that it will start a local HTTP service at http://$host:$port, then runs npm start in a local server directory. However, generate_config for http emits a client config pointing to https://open.lannlife.com/mcp instead of the local host/port service. This is an active contradiction between the script's documented local HTTP mode and the configuration it generates for that mode.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script unconditionally writes to mcp-config.json using shell redirection, which can overwrite an existing file in the current directory. Although it prints a success message afterward, there is no prior warning, confirmation prompt, or comment disclosing the potential data-loss behavior before the write occurs.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This test script sends booking data, including a phone number, to an external production endpoint and also prints the payload locally. In skill/repository context, that creates a real data-exfiltration and privacy risk because running the test can transmit personal data off-host and may generate unintended real bookings against a live service.

Content

Scanner excerpt · scripts/test_booking.py (reported line 86)May include surrounding context.

python
print(json.dumps(payload, indent=2, ensure_ascii=False))

    try:
        response = requests.post(
            API_ENDPOINT,
            headers=HEADERS,
            json=payload,

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This second POST path also transmits booking-related data externally to the live API, here with intentionally incomplete parameters for negative testing. Even though the payload is smaller, it still discloses user/store data to a third-party endpoint and can exercise production-side behavior unexpectedly, which is risky in an agent skill context.

Content

Scanner excerpt · scripts/test_booking.py (reported line 197)May include surrounding context.

python
print(json.dumps(payload, indent=2, ensure_ascii=False))

    try:
        response = requests.post(
            API_ENDPOINT,
            headers=HEADERS,
            json=payload,

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The script performs an outbound POST to an external remote service and includes booking details in the request body. In this skill context, that behavior is expected for booking functionality, but it is still security-relevant because execution causes real network transmission of potentially sensitive data and operational side effects against a live service.

Content

Scanner excerpt · scripts/test_booking.sh (reported line 48)May include surrounding context.

sh
}
EOF

    response=$(curl -s -w "\n%{http_code}" -X POST "$API_ENDPOINT" \
        -H "Content-Type: application/json" \
        -d "{
            \"mobile\": \"$mobile\",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script sends booking data, including a phone number, to a live production endpoint and even includes a plausibly real-looking mobile number in the test data. Running it can transmit personal data and may create actual reservations without clearly warning the operator or requiring explicit confirmation of the privacy and side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill as a Chinese-language booking skill without indicating that users may choose another language or locale. Under the policy for natural-language constraints, this can be a locale/language restriction unless explicitly documented as region-specific or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This JSON file contains all user-facing textual values such as store names, addresses, and transit directions exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says the skill covers stores in '上海、杭州、成都等多城市', implying a multi-city footprint, but this data file specifically includes additional cities such as 苏州 (L379-L396), 武汉 (L219-L224), 宁波 (L571-L576), and 深圳 (L595-L600) that are not reflected in the example city list. This is a mild description-behavior mismatch because the code/data scope is broader than the concrete geographic examples presented in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.