【美团专属大额券 + 一键直达短链路 + 自动提醒长收益】 核心功能: ① 领券超便捷 —— 覆盖吃喝玩乐全场景,点一下就能领,领完马上用,无需等待; ② 优惠早知道 —— 每日热点活动一手掌握,专属链接直达,抢券快人一步; ③ 省钱自动化 —— 设置一次,每天自动提醒你领券,再也不怕错过任何福利。 触发词(共4...
Security Analysis
high confidenceThis coupon skill needs Review because it handles phone/SMS login and stored account tokens while disabling HTTPS checks in key auth calls and adding diagnostics, updates, and reminders beyond the simple coupon pitch.
Coupon claiming and reminders are coherent with the stated purpose, but the artifacts also implement SMS account login, user_token/device_token storage, token validation, auth-log diagnostics, and self-update behavior while the public metadata marks high_sensitive as false and does not clearly foreground those sensitive capabilities.
The trigger set is broad and includes generic shopping phrases, and the skill instructs the agent to keep technical operations silent while initiating flows that can request a phone number, SMS code, token checks, and reminder setup. Consent text exists, but activation and disclosure are under-scoped for the sensitivity.
The package is a normal skill artifact with local scripts, but SKILL.md includes runtime version checks and user-approved update commands via external skill tools, which adds supply-chain risk outside the narrow coupon workflow.
The skill writes authentication state under the user's home directory, logs auth and coupon activity under temp storage, creates long-term memory entries, can schedule recurring reminders, and sends phone/token/device data to remote Meituan endpoints. Some of this is purpose-aligned, but disabled TLS verification on token verification and SMS sending is disproportionate and unsafe.
Persistent user_token and device_token handling is central to the implementation; device_token intentionally survives logout, and Doctor diagnostics can read raw local tokens and decrypted logs. That is high-impact account state for a coupon skill and needs stronger scoping and controls.
Guidance
Review carefully before installing. This skill may ask for your Meituan phone number and SMS code, store login tokens and a device identifier locally, contact Meituan endpoints, keep local diagnostic logs, and create recurring reminders. Avoid using it until HTTPS certificate verification is fixed and raw-token diagnostics are removed or tightly gated; only use it if you trust the publisher and understand how to clear both login and device state.
Latest Release
v1.0.0
**meituan-union-coupon-skill v1.0.0 changelog** - Initial release under the new name: 美团分销推广 Skill(meituan-fenxiao-promotion-coupon) - Enables quick claiming of exclusive large-denomination Meituan coupons across all major consumer scenarios - Offers automatic daily reminders to help users never miss new benefits - Integrates strict step-by-step execution flow and precise user interaction logic - Includes comprehensive error handling, privacy notices, and protocol agreement workflow - Supports 44 trigger phrases for seamless user activation and coupon claiming
Popular Skills
Published by @meituan-union on ClawHub