meituan-coupon-get-tool
What this skill does
A tool for claiming Meituan coupons and querying historical coupon records. It interacts with Meituan's API to issue coupons and retrieve user data.
github/leoyeai - Data Exfiltration - 2.1k stars
Threat analysis
Skill info
pkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=meituan-coupon-get-toolAssessments (3)
Data Exfiltration
Data Exfiltration via local-llm-review
scripts/auth.py
The script contains logic for managing user tokens and device tokens, which could be used to exfiltrate sensitive user data if not properly secured.Insecure API Communication
Insecure API Communication via local-llm-review
scripts/issue.py
The script communicates with Meituan's API at 'https://peppermall.meituan.com' without any indication of using HTTPS or secure communication protocols.Configuration File Exposure
Configuration File Exposure via local-llm-review
scripts/config.json
The configuration file contains a 'subChannelCode' value, which could be sensitive if exposed to unauthorized users.Badge
Add the Anomity scan badge for meituan-coupon-get-tool to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of meituan-coupon-get-tool? Report an issue or request a rescan.




