Back to skill

Security audit

携程酒店搜索

Security checks for vulnerabilities and agentic risk

Overview

This Ctrip hotel-search skill has useful travel automation code, but it needs review because it handles account/API credentials insecurely, includes under-disclosed third-party search scripts, and overstates some live-search capability.

Install only if you are comfortable with an agent controlling a browser logged into your Ctrip account. Do not put real account passwords or API keys in project files; use environment variables or a secret manager, keep config files out of version control, and verify all hotel results directly on Ctrip before relying on them. Treat the MATON/Brave scripts and demo hotel recommendations as separate or non-live paths unless the publisher clearly documents them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:29
Finding

Plaintext Ctrip Credentials Stored in Project Configuration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/details.js:12
Finding

Unvalidated Navigation to Page-Supplied URLs in an Authenticated Browser Context

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
api_key_config.py:1
Finding

MATON API Key Encouraged to Be Stored Directly in Source Code

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially differs from the declared skill purpose: instead of automating Ctrip hotel search and detail retrieval, it sends arbitrary queries to a third-party Brave search gateway. This is dangerous because users and orchestrators may grant permissions or trust based on the manifest, while the code actually exfiltrates user queries to an unrelated external service and may return irrelevant or manipulated results.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states the skill is completed even though the body says the primary search functionality is unavailable due to lack of access to Ctrip. This inconsistency can mislead operators into relying on the skill for automated browsing or hotel comparison when it can only provide manual instructions, creating integrity and trust issues in agent workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file claims the skill is complete and ready, while the document itself admits the core automated capability cannot access Ctrip and requires manual user action. This is dangerous because it misrepresents operational security and capability, which can cause downstream agents or users to trust, invoke, or deploy the skill under false assumptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is natural-language documentation, and its content appears to require Chinese as the only operating/documentation language. Under the policy, forcing a specific language without user opt-in or a documented, justified locale scope is a violation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The documentation instructs users to run npx playwright install without pinning an exact package version. If playwright is resolved from the network at execution time, users may install an unexpected or compromised version, creating a supply-chain risk in a workflow that already handles browser automation and likely user credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The quick-start guide instructs users to place live Ctrip credentials directly into a local config.json file during setup, but the setup step does not prominently warn about plaintext secret storage, accidental commits, or file-sharing exposure. In the context of a browser automation skill that logs into a real consumer account, this increases the chance of credential compromise and downstream account misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description advertises automatic login and instructs users to store Ctrip credentials in config.json, but it does not prominently warn users about the security implications of automated credential use and local plaintext secret storage. This can lead users to expose account credentials or run the skill without understanding that it will authenticate to a third-party service on their behalf.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README instructs users to run npx playwright without pinning a specific package version, which can cause execution of an unexpected or newly published package version at install time. In a skill that automates browser actions and handles account credentials, supply-chain drift increases risk because compromised or malicious upstream code could gain access to authentication context or local system data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises capabilities that inherently require network access and likely environment-based secrets or credentials, but the manifest does not declare any explicit tool scope or permissions. This creates an opaque trust boundary: reviewers and users cannot clearly see what external access the skill expects, which increases the risk of hidden data access or over-broad execution when the skill is installed or run.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Browser automation against a third-party travel site can expose search history, account activity, personal preferences, and potentially session data, yet the skill provides no privacy or account-activity warning. Given the claimed automation of a live user account, the absence of disclosure increases the chance of unintended data exposure or account actions that the user did not fully understand.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Browser automation against a third-party travel site can expose search history, account activity, personal preferences, and potentially session data, yet the skill provides no privacy or account-activity warning. Given the claimed automation of a live user account, the absence of disclosure increases the chance of unintended data exposure or account actions that the user did not fully understand.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The guide tells users to run npx playwright without pinning a specific version, which can fetch and execute whatever version is current at install time. In a skill that relies on browser automation and is intended for end users, this increases supply-chain risk and weakens reproducibility if a compromised or breaking upstream release is published.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation instructs users to place their Ctrip account credentials into config.json with no warning about plaintext secret handling, file permissions, or exclusion from version control. Because this skill automates login to a real travel account, exposed credentials could enable account takeover, access to booking history and personal data, or unauthorized purchases.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially differs from the advertised skill behavior: instead of Ctrip browser automation, login, hotel detail retrieval, and comparison analysis, it sends a generic query to a third-party search API. This is dangerous because users may grant trust, credentials, or permissions based on the manifest while the code performs unrelated external data access, creating a supply-chain and transparency risk even if the current code is not overtly malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The hard-coded query content is in Chinese and the request explicitly sets search_lang=zh and country=CN. This creates a language/locale policy issue because the skill enforces a specific locale with no user opt-in or documented reason that it must be China-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code relies on an unrelated third-party API endpoint for its core behavior without that dependency being justified by the stated purpose. Hidden or unexplained outbound dependencies are risky because they can exfiltrate user queries and undermine expected trust boundaries, especially when the skill claims a different operational model.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code requires a generic API credential from the environment for a service not justified by the stated Ctrip automation purpose. In a mismatched skill, undeclared credential use increases the risk of hidden external dependencies, unintended data sharing, and misuse of secrets under a misleading capability description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The request parameters hard-code search_lang='zh' and country='CN', which imposes a specific language and locale on every search. This matches the policy category for language/locale constraints because the code does not offer user opt-in or explain a region-specific requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code extracts review author names, review text, ratings, and dates from the page, which is user-generated content and may implicate privacy expectations. Although the file logs that it is fetching reviews, there is no warning or disclosure that personal or user-authored data will be collected and returned.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.