Hotel

Security checks across malware telemetry and agentic risk

Overview

This is a local hotel-planning helper that stores trip, hotel, and preference details in clearly disclosed local JSON files.

Install only if you are comfortable with hotel plans, dates, budgets, notes, and preferences being saved locally under ~/.openclaw/workspace/memory/hotel. Avoid storing secrets or highly sensitive personal details in hotel notes, and delete those JSON files when you no longer want the data retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill declares local file storage and exposes multiple scripts that read and write user trip and preference data, but it does not declare corresponding permissions. That mismatch can hide the skill's real capabilities from the platform or user review process, reducing transparency and making unintended data access harder to govern.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The manifest description uses very broad activation language such as 'use whenever the user mentions hotels, where to stay... or choosing the best stay for a trip,' which could cause the skill to trigger during ordinary travel discussion rather than clear intent to use a hotel-planning tool. Over-broad triggering increases the chance the skill accesses or stores sensitive travel plans and preferences when the user did not explicitly request that behavior.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal