Back to skill

Security audit

McDonald's China

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it asks users to install an unpinned third-party CLI and give it an account token, with limited warning around account-changing coupon actions.

Review the upstream mcd-cn project and Homebrew tap before installing, use a minimally scoped token if available, avoid storing the token in a committed .env file, and treat auto-bind-coupons as an account-changing action rather than a read-only lookup.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned CLI Installation from a Mutable Third-Party Homebrew Tap

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises mcd-cn auto-bind-coupons as a common command but does not clearly warn that it performs an account-affecting action rather than a read-only lookup. In an agent context, this increases the chance of unintended coupon claiming or account state changes if a user or downstream automation assumes all listed commands are safe informational queries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.